STIGQter STIGQter: STIG Summary: Adobe ColdFusion Security Technical Implementation Guide Version: 1 Release: 2 Benchmark Date: 01 Jul 2026:

ColdFusion must be configured to set the HTTPOnly attribute on session cookies to prevent client-side scripts from accessing the cookies.

DISA Rule

SV-279108r1171098_rule

Vulnerability Number

V-279108

Group Title

SRG-APP-000516-AS-000237

Rule Version

APAS-CF-001070

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure Session Cookie setting.

1. From the Admin Console Landing Screen, navigate to Server Settings >> Memory Variables.

2. Locate the options labeled "Session Cookie Settings".

3. Enable (check) the"HTTPOnly" option.

4. Select "Submit Changes".

Check Contents

Verify Session Cookie setting "HTTPOnly".

1. From the Admin Console Landing Screen, navigate to Server Settings >> Memory Variables.

2. Locate the options labeled "Session Cookie Settings".

If "HTTPOnly" setting is not enabled (checked) for session cookies, this is a finding.

Vulnerability Number

V-279108

Documentable

False

Rule Version

APAS-CF-001070

Severity Override Guidance

Verify Session Cookie setting "HTTPOnly".

1. From the Admin Console Landing Screen, navigate to Server Settings >> Memory Variables.

2. Locate the options labeled "Session Cookie Settings".

If "HTTPOnly" setting is not enabled (checked) for session cookies, this is a finding.

Check Content Reference

M

Target Key

5724