STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must ensure that ColdFusion Package Manager (cfpm) packages are transmitted using encrypted protocols.

DISA Rule

SV-279097r1171591_rule

Vulnerability Number

V-279097

Group Title

SRG-APP-000440-AS-000167

Rule Version

APAS-CF-000895

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Package Manager Settings.

1. From the Admin Console Landing Screen, navigate to Package Manager >> Settings.

2. Enter an "HTTPS" entry into each of the Site URL fields.

3. Select "Submit Changes".

Check Contents

Verify Package Manager Settings.

From the Admin Console Landing Screen, navigate to Package Manager >> Settings.

If any Site URL is configured with an "HTTP" , this is a finding.

Vulnerability Number

V-279097

Documentable

False

Rule Version

APAS-CF-000895

Severity Override Guidance

Verify Package Manager Settings.

From the Admin Console Landing Screen, navigate to Package Manager >> Settings.

If any Site URL is configured with an "HTTP" , this is a finding.

Check Content Reference

M

Target Key

5724