STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must limit the request throttle memory.

DISA Rule

SV-279088r1171038_rule

Vulnerability Number

V-279088

Group Title

SRG-APP-000435-AS-000163

Rule Version

APAS-CF-000820

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Maximum Request Throttle Memory settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Settings.

2. Set "Request Throttle Memory" to the required amount.

3. Select "Submit Changes".

Check Contents

Verify Request Throttle Memory settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Settings.

2. Interview the administrator to determine what the maximum post data size is required for the hosted applications.

If the "Request Throttle Memory" is not set to a 10 to 25 times multiple of the larger of "Request Throttle Threshold" or the maximum request size, this is a finding.

Vulnerability Number

V-279088

Documentable

False

Rule Version

APAS-CF-000820

Severity Override Guidance

Verify Request Throttle Memory settings.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Settings.

2. Interview the administrator to determine what the maximum post data size is required for the hosted applications.

If the "Request Throttle Memory" is not set to a 10 to 25 times multiple of the larger of "Request Throttle Threshold" or the maximum request size, this is a finding.

Check Content Reference

M

Target Key

5724