STIGQter STIGQter: STIG Summary: Adobe ColdFusion 11 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 26 Jan 2018:

ColdFusion must disable Flash Remoting support.

DISA Rule

SV-76897r1_rule

Vulnerability Number

V-62407

Group Title

SRG-APP-000141-AS-000095

Rule Version

CF11-03-000097

Severity

CAT I

CCI(s)

Weight

10

Fix Recommendation

Navigate to the "Flex Integration" page under the "Data & Services" menu. Uncheck the "Enable Flash Remoting" option and select the "Submit Changes" button.

Check Contents

Ask the administrator if ColdFusion server monitoring is being used or if flex remoting is being used by any hosted applications.

If ColdFusion server monitoring is being used or hosted applications are using flash remoting, this is not a finding.

Within the Administrator Console, navigate to the "Flex Integration" page under the "Data & Services" menu.

If the "Enable Flash Remoting" option is checked, this is a finding.

Vulnerability Number

V-62407

Documentable

False

Rule Version

CF11-03-000097

Severity Override Guidance

Ask the administrator if ColdFusion server monitoring is being used or if flex remoting is being used by any hosted applications.

If ColdFusion server monitoring is being used or hosted applications are using flash remoting, this is not a finding.

Within the Administrator Console, navigate to the "Flex Integration" page under the "Data & Services" menu.

If the "Enable Flash Remoting" option is checked, this is a finding.

Check Content Reference

M

Target Key

2661

Comments