UCF STIG Viewer Logo

ColdFusion must have example gateway instances removed.


Overview

Finding ID Version Rule ID IA Controls Severity
V-62449 CF11-03-000119 SV-76939r1_rule Medium
Description
ColdFusion is installed with sample data services, gateway services, and collections. These can be used in a development environment to learn how to use and develop applications and services, but these samples are not tested and patched for security issues. Allowing them to be available on a production system provides a gateway to an attacker to the application server and to those systems connected to ColdFusion. To alleviate this issue, sample code and services must be deleted.
STIG Date
Adobe ColdFusion 11 Security Technical Implementation Guide 2017-12-31

Details

Check Text ( C-63253r1_chk )
Several sample services are installed with the ColdFusion server. From the Administrator Console, go to the "Gateway Instances" page under the "Event Gateways" menu.

If the Gateway Instance SMS Menu App. exists, this is a finding.
Fix Text (F-68369r1_fix)
Remove the sample gateway instances by navigating to the "Gateway Instances" page under the "Event Gateways" menu. Delete the Gateway Instance SMS Menu App.