ColdFusion must have the CFSTAT feature disabled when not in use.
Severity | Group ID | Group Title | Version | Rule ID | Date | STIG Version |
|---|---|---|---|---|---|---|
| low | V-279052 | SRG-APP-000141-AS-000095 | APAS-CF-000285 | SV-279052r1171523_rule | 2025-12-19 | 1 |
| Description |
|---|
| Application servers provide a myriad of differing processes, features, and functionalities. Some of these processes may be deemed to be unnecessary or too unsecure to run on a production DOD system. ColdFusion offers the CFSTAT command-line utility to retrieve real-time performance metrics for the system. This feature uses a socket connection to obtain the metrics which can also be used by an attacker to observe privileged information about the system and must be disabled if not in use. |
| ℹ️ Check |
|---|
| Verify the CFSTAT feature. From the Admin Console Landing Screen, navigate to Debug & Logging >> Debug Output Settings. If CFSTAT is not in use and "Enable CFSTAT" is checked, this is a finding. |
| ✔️ Fix |
|---|
| Configure the CFSTAT feature. 1. From the Admin Console Landing Screen, navigate to Debug & Logging >> Debug Output Settings. 2. Uncheck "Enable CFSTAT". 3. Select "Submit Changes". |