STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must be set to automatically check for updates.

DISA Rule

SV-279100r1171595_rule

Vulnerability Number

V-279100

Group Title

SRG-APP-000456-AS-000266

Rule Version

APAS-CF-000935

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure ColdFusion to check for updates.

1. If the ColdFusion server has access to a patch repository:

a. From the Admin Console Landing Screen, navigate to Package Manager >> Settings.

b. Enable the "Automatically Check for Updates" option by checking the box.

c. Save the configuration.

2. If the ColdFusion server does not have access to a patch repository:

a. Develop and maintain documented procedures describing the manual update process.

b. Ensure the documentation includes the location where patches and updates will be obtained (e.g., Adobe website, internal repository) and the frequency with which updates will be checked (e.g., weekly, monthly).

Check Contents

Verify the ColdFusion server is configured to check for updates, either automatically or through a documented manual process.

1. Confirm whether the ColdFusion server has access to either the Adobe patch repository or an internally maintained patch repository. This can be verified by interviewing the system administrator (SA) or reviewing ColdFusion baseline documentation.

2. If the server has access to a patch repository, from the Admin Console Landing Screen, navigate to Package Manager >> Settings.

3. Verify "Automatically Check for Updates" is enabled (checked).

If the server has access to a patch repository and "Automatically Check for Updates" is not enabled, this is a finding.

4. If the server does not have access to a patch repository, confirm that a documented manual process exists for checking and retrieving updates. The documented process must specify where to obtain updates, and how often updates are to be checked.

If no documented process exists, or if the process does not include both location and frequency, this is a finding.

Vulnerability Number

V-279100

Documentable

False

Rule Version

APAS-CF-000935

Severity Override Guidance

Verify the ColdFusion server is configured to check for updates, either automatically or through a documented manual process.

1. Confirm whether the ColdFusion server has access to either the Adobe patch repository or an internally maintained patch repository. This can be verified by interviewing the system administrator (SA) or reviewing ColdFusion baseline documentation.

2. If the server has access to a patch repository, from the Admin Console Landing Screen, navigate to Package Manager >> Settings.

3. Verify "Automatically Check for Updates" is enabled (checked).

If the server has access to a patch repository and "Automatically Check for Updates" is not enabled, this is a finding.

4. If the server does not have access to a patch repository, confirm that a documented manual process exists for checking and retrieving updates. The documented process must specify where to obtain updates, and how often updates are to be checked.

If no documented process exists, or if the process does not include both location and frequency, this is a finding.

Check Content Reference

M

Target Key

5724