STIGQter STIGQter: STIG Summary: Adobe ColdFusion 11 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 26 Jan 2018:

ColdFusion must remove software components after updated versions have been installed.

DISA Rule

SV-77031r1_rule

Vulnerability Number

V-62541

Group Title

SRG-APP-000454-AS-000268

Rule Version

CF11-06-000225

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to the "Updates" page under the "Server Update" menu within the Administrator Console. Within the "Installed Updates" tab, locate the backup directory location for any updates installed. On the server running the ColdFusion server, remove all backup directories for any updates installed.

Note: Do not remove the backup directory for an update until the update has been tested and verified that the ColdFusion server is operating correctly.

Check Contents

Within the Administrator Console, navigate to the "Updates" page under the "Server Update" menu. Within the "Installed Updates" tab, locate the backup directory location for each update that is installed. On the server running the ColdFusion server, verify that the backup directories do not exist for any of the updates.

If all updates have been tested/verified and any of the backup directories exist, this is a finding.

Note: Do not remove the backup directory for an update until the update has been tested and verified that the ColdFusion server is operating correctly.

Vulnerability Number

V-62541

Documentable

False

Rule Version

CF11-06-000225

Severity Override Guidance

Within the Administrator Console, navigate to the "Updates" page under the "Server Update" menu. Within the "Installed Updates" tab, locate the backup directory location for each update that is installed. On the server running the ColdFusion server, verify that the backup directories do not exist for any of the updates.

If all updates have been tested/verified and any of the backup directories exist, this is a finding.

Note: Do not remove the backup directory for an update until the update has been tested and verified that the ColdFusion server is operating correctly.

Check Content Reference

M

Target Key

2661

Comments