STIGQter STIGQter: STIG Summary: Adobe ColdFusion 11 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 26 Jan 2018:

ColdFusion must set session cookies as browser session cookies.

DISA Rule

SV-76965r1_rule

Vulnerability Number

V-62475

Group Title

SRG-APP-000223-AS-000150

Rule Version

CF11-05-000169

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to the "Memory Variables" page under the "Server Settings" menu. Set the parameter "Cookie Timeout" to -1 and select the "Submit Changes" button.

Check Contents

Within the Administrator Console, navigate to the "Memory Variables" page under the "Server Settings" menu.

If "Cookie Timeout" is not set to -1, this is a finding.

Vulnerability Number

V-62475

Documentable

False

Rule Version

CF11-05-000169

Severity Override Guidance

Within the Administrator Console, navigate to the "Memory Variables" page under the "Server Settings" menu.

If "Cookie Timeout" is not set to -1, this is a finding.

Check Content Reference

M

Target Key

2661

Comments