STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

Installed versions of ColdFusion must be supported by the vendor.

DISA Rule

SV-279102r1171420_rule

Vulnerability Number

V-279102

Group Title

SRG-APP-000516-AS-000237

Rule Version

APAS-CF-000995

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Upgrade ColdFusion to a supported version or uninstall the application. All upgrade or uninstall actions must be executed in accordance with an approved application management plan.

Check Contents

Verify the ColdFusion version.

1. Open the ColdFusion Administrator Console.

2. Identify the version of ColdFusion currently installed (displayed in the upper-right system information icon).

3. Navigate to Adobe's official "Product and technical support periods" page:
https://helpx.adobe.com/support/programs/eol-matrix.html

4. Locate the ColdFusion product version in the matrix and review the listed "End of Core Support" and/or "End of Extended Support" dates.

If the version of ColdFusion in use has passed its support period (core or extended), this is a finding.

Vulnerability Number

V-279102

Documentable

False

Rule Version

APAS-CF-000995

Severity Override Guidance

Verify the ColdFusion version.

1. Open the ColdFusion Administrator Console.

2. Identify the version of ColdFusion currently installed (displayed in the upper-right system information icon).

3. Navigate to Adobe's official "Product and technical support periods" page:
https://helpx.adobe.com/support/programs/eol-matrix.html

4. Locate the ColdFusion product version in the matrix and review the listed "End of Core Support" and/or "End of Extended Support" dates.

If the version of ColdFusion in use has passed its support period (core or extended), this is a finding.

Check Content Reference

M

Target Key

5724