STIGQter STIGQter: STIG Summary:

Adobe ColdFusion Security Technical Implementation Guide

Version: 1

Release: 2 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-279030r1171489_ruleColdFusion must limit concurrent sessions to the Administrator Console.
SV-279031r1171492_ruleThe ColdFusion built-in Tomcat Web Server must use FIPS-validated ciphers on secured connectors.
SV-279032r1171325_ruleColdFusion must require enforced authentication.
SV-279033r1171269_ruleColdFusion must not have local users.
SV-279034r1171436_ruleColdFusion must produce log records containing information to establish what type of events occurred.
SV-279035r1171616_ruleColdFusion must log scheduled tasks.
SV-279036r1171601_ruleThe ColdFusion log information must be protected from any type of unauthorized read access by having file ownership set properly.
SV-279037r1171603_ruleThe ColdFusion file ownership and permissions must be restricted to prevent unauthorized access to log tools.
SV-279038r1171464_ruleBefore installing or upgrading ColdFusion, the integrity of the installation package must be manually verified.
SV-279039r1171605_ruleCritical ColdFusion directories must have secure file system permissions and ownership.
SV-279040r1171341_ruleColdFusion must configure WebSocket Service.
SV-279041r1171343_ruleColdFusion must have Event Gateway Services disabled when not in use.
SV-279042r1171505_ruleColdFusion must have Remote Development Services (RDS) disabled.
SV-279043r1171348_ruleColdFusion must have example services removed.
SV-279044r1171508_ruleColdFusion must disable all remote and client-side debugging features, including Remote Inspection, Robust Exception Information, AJAX Debug Log Window, and Line Debugging.
SV-279045r1171287_ruleColdFusion must have any unused mappings removed.
SV-279046r1171510_ruleColdFusion must have Central Configuration Server (CCS) disabled.
SV-279047r1171513_ruleColdFusion must have only approved Tomcat connectors enabled.
SV-279048r1171516_ruleColdFusion must have Tomcat configured with deployXML disabled.
SV-279049r1171519_ruleColdFusion must be configured with autoDeploy disabled.
SV-279050r1171521_ruleColdFusion must be configured with secure and approved server settings to enforce application hardening, input validation, error handling, and protection against common web vulnerabilities.
SV-279051r1171473_ruleColdFusion must have the sample data directories removed.
SV-279052r1171523_ruleColdFusion must have the CFSTAT feature disabled when not in use.
SV-279053r1171525_ruleColdFusion must disable the In-Memory File System.
SV-279054r1171443_ruleColdFusion must restrict unauthorized remote access to the ColdFusion Administrator Console and ensure all ports used are approved and properly secured.
SV-279055r1171527_ruleColdFusion must be using an enterprise solution for authentication.
SV-279056r1171606_ruleWeb services using Simple Object Access Protocol (SOAP) to access sensitive data must be secured with WS-Security.
SV-279057r1171529_ruleColdFusion must store only encrypted representations of passwords.
SV-279058r1207648_ruleColdFusion must transmit only encrypted representations of passwords to NoSQL data sources.
SV-279059r1207648_ruleColdFusion must only transmit encrypted representations of passwords to the Solr Server.
SV-279060r1207648_ruleColdFusion must transmit only encrypted representations of passwords to the mail server.
SV-279061r1207648_ruleColdFusion must only transmit encrypted representations of passwords to the caching server.
SV-279062r1207648_ruleJVM Arguments must be configured for encryption.
SV-279063r1171542_ruleColdFusion must be configured to use only DOD-approved keystores and truststores containing certificates issued by a DOD Public Key Infrastructure (PKI) Certificate Authority (CA), and all keystore and truststore files must be protected by file system permissions that prevent unauthorized access or modification.
SV-279064r1171544_ruleThe ColdFusion Administrator Console must be hosted on a management network.
SV-279065r1171383_ruleColdFusion must have sandboxes enabled and defined.
SV-279066r1171607_ruleColdFusion must separate the hosted application from the web server.
SV-279067r1171547_ruleColdFusion must be configured to mutually authenticate connecting proxies and load balancers.
SV-279068r1172825_ruleColdFusion must generate a unique session identifier using a FIPS 140-2/140-3 or higher approved random number generator.
SV-279069r1171551_ruleColdFusion systems must provide clustering.
SV-279070r1172833_ruleColdFusion must be configured to support integration with a third-party Security Information and Event Management (SIEM) to support notifications.
SV-279071r1171608_ruleColdFusion must have the Tomcat DefaultServlet debug parameter disabled.
SV-279072r1170990_ruleThe ColdFusion error messages must be restricted to only authorized users.
SV-279073r1171560_ruleColdFusion must set a maximum session timeout value.
SV-279074r1171609_ruleColdFusion must control remote access to the Administrator Console.
SV-279075r1171564_ruleColdFusion must control remote access to Exposed Services.
SV-279076r1172835_ruleColdFusion must allocate log record storage capacity.
SV-279077r1171570_ruleColdFusion must record time stamps for log records that can be mapped system time.
SV-279078r1172827_ruleFor PKI-based authentication, ColdFusion must implement a local cache of revocation data to support path discovery and validation in case of the inability to access revocation information via the network.
SV-279079r1171576_ruleColdFusion must set Request Tuning configurations.
SV-279080r1171402_ruleColdFusion must limit the maximum number of threads available for CFTHREAD.
SV-279081r1171481_ruleColdFusion must limit the maximum number of Web Service requests.
SV-279082r1171310_ruleColdFusion must limit the maximum number of ColdFusion Component (CFC) function requests.
SV-279083r1171449_ruleColdFusion must configure Data Sources to limit SQL command and configure timeout.
SV-279084r1171578_ruleColdFusion must not store user information in the server registry.
SV-279085r1171029_ruleColdFusion must limit the in-memory size of the virtual file system.
SV-279086r1171032_ruleColdFusion must limit the default maximum thread count for parallel functions.
SV-279087r1171035_ruleColdFusion must limit the maximum post data size.
SV-279088r1171038_ruleColdFusion must limit the request throttle memory.
SV-279089r1171580_ruleColdFusion must set an organization defined maximum number of cached templates.
SV-279090r1171582_ruleColdFusion must set an organization defined maximum JVM heap size.
SV-279091r1171452_ruleColdFusion must set a nonzero timeout for web services.
SV-279092r1171584_ruleJVM Arguments must be configured for Transport Layer Security (TLS) 1.2 or higher.
SV-279093r1171053_ruleColdFusion must configure Lightweight Directory Access Protocol (LDAP) for Transport Layer Security (TLS).
SV-279094r1171587_ruleColdFusion must remove all export ciphers to protect the confidentiality and integrity of transmitted information.
SV-279095r1171617_ruleJVM arguments must be configured to use approved cryptographic mechanisms to protect data in transit.
SV-279096r1171589_ruleColdFusion must encrypt patch retrieval.
SV-279097r1171591_ruleColdFusion must ensure that ColdFusion Package Manager (cfpm) packages are transmitted using encrypted protocols.
SV-279098r1172830_ruleThe ColdFusion administrator must be using HTTPS to maintain the confidentiality and integrity of information during reception.
SV-279099r1172837_ruleColdFusion Backup Directory must be deleted.
SV-279100r1171595_ruleColdFusion must be set to automatically check for updates.
SV-279101r1171077_ruleColdFusion must have notifications enabled when a server update is available.
SV-279102r1171420_ruleInstalled versions of ColdFusion must be supported by the vendor.
SV-279103r1171485_ruleColdFusion must execute as a nonprivileged user.
SV-279104r1171486_ruleThe ColdFusion Root Administrator account must have a unique username.
SV-279105r1171428_ruleColdFusion must protect newly created objects.
SV-279106r1171597_ruleColdFusion must be configured to set the cookie settings.
SV-279107r1208176_ruleColdFusion must be configured to enable Cross-Origin Resource Sharing (CORS) to allow mobile applications to access resources from different origins securely.
SV-279108r1171098_ruleColdFusion must be configured to set the HTTPOnly attribute on session cookies to prevent client-side scripts from accessing the cookies.
SV-279109r1171101_ruleColdFusion must be configured to set the Secure attribute on session cookies to ensure that cookies are only transmitted over secure HTTPS connections.
SV-279110r1171432_ruleColdFusion must have the Java Runtime Environment (JRE) updated to the latest version.
SV-279111r1171107_ruleColdFusion must have CFIDE blocked in the uriworkermap.properties file.
SV-279112r1171599_ruleColdFusion must include only approved trust anchors in trust stores or certificate stores managed by the organization.
SV-279129r1171553_ruleColdFusion must not install the Performance Monitoring Toolset (PMT) Agent Package.