STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must set a nonzero timeout for web services.

DISA Rule

SV-279091r1171452_rule

Vulnerability Number

V-279091

Group Title

SRG-APP-000435-AS-000163

Rule Version

APAS-CF-000845

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure web services timeout.

1. From the Admin Console Landing Screen, navigate to Data & Services >> Web Services.

2. For each Active ColdFusion Web Services:

a. Click "Edit".

b. Set the "Timeout" setting to a duration appropriate for the service.

c. Select "Update Web Service".

Check Contents

Verify web services timeout.

1. From the Admin Console Landing Screen, navigate to Data & Services >> Web Services.

2. For each Active ColdFusion Web Services:

a. Click "Edit".

b. Review the "Timeout" for each of the "Active ColdFusion Web Services" entries.

If any of the timeout values are set to 0, this is a finding.

Vulnerability Number

V-279091

Documentable

False

Rule Version

APAS-CF-000845

Severity Override Guidance

Verify web services timeout.

1. From the Admin Console Landing Screen, navigate to Data & Services >> Web Services.

2. For each Active ColdFusion Web Services:

a. Click "Edit".

b. Review the "Timeout" for each of the "Active ColdFusion Web Services" entries.

If any of the timeout values are set to 0, this is a finding.

Check Content Reference

M

Target Key

5724