STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

JVM arguments must be configured to use approved cryptographic mechanisms to protect data in transit.

DISA Rule

SV-279095r1171617_rule

Vulnerability Number

V-279095

Group Title

SRG-APP-000440-AS-000167

Rule Version

APAS-CF-000885

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Configure JVM Arguments for Crypto.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.

2. Amend JVM arguments with "-Dcoldfusion.enablefipscrypto=true".

3. Click "Submit Changes".

4. If not using Enterprise Edition or cryptographic mechanisms are not available, reinstall with Enterprise Edition.

Check Contents

Verify JVM Arguments for Crypto.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.

If the JVM argument contains "-Dcoldfusion.enablefipscrypto=false" or
"-Dcoldfusion.enablefipscrypto" is missing, this is a finding.

2. Observe the ColdFusion edition at the top of the Administrator Console.

If the edition is "Standard", this is a finding.

Vulnerability Number

V-279095

Documentable

False

Rule Version

APAS-CF-000885

Severity Override Guidance

Verify JVM Arguments for Crypto.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Java and JVM.

If the JVM argument contains "-Dcoldfusion.enablefipscrypto=false" or
"-Dcoldfusion.enablefipscrypto" is missing, this is a finding.

2. Observe the ColdFusion edition at the top of the Administrator Console.

If the edition is "Standard", this is a finding.

Check Content Reference

M

Target Key

5724