UCF STIG Viewer Logo

ColdFusion must have Sandbox Security enabled.


Overview

Finding ID Version Rule ID IA Controls Severity
V-62439 CF11-03-000114 SV-76929r1_rule Medium
Description
Application isolation allows multiple applications to run on the same hosting operating system, web server and application server. Typical reasons to isolate applications are to separate different application user bases, data security levels, protect application resources, and to give least privileges to each application to system resources. Application isolation will also contain an application that has been compromised from compromising other hosted applications. To allow sandboxing to be implemented, the feature must be enabled.
STIG Date
Adobe ColdFusion 11 Security Technical Implementation Guide 2017-12-31

Details

Check Text ( C-63243r1_chk )
Within the Administrator Console, navigate to the "Sandbox Security" page under the "Security" menu.

If "Enable ColdFusion Sandbox Security" is unchecked, this is a finding.
Fix Text (F-68359r1_fix)
Navigate to the "Sandbox Security" page under the "Security" menu. Check "Enable ColdFusion Sandbox Security" and select the "Submit Changes" button.