STIGQter STIGQter: STIG Summary: Adobe ColdFusion 11 Security Technical Implementation Guide Version: 1 Release: 4 Benchmark Date: 26 Jan 2018:

ColdFusion must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.

DISA Rule

SV-76843r1_rule

Vulnerability Number

V-62353

Group Title

SRG-APP-000033-AS-000024

Rule Version

CF11-01-000007

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Navigate to the "User Manager" page under the "Security" menu and review the roles assigned to each user. Enable only those roles for each user approved by the ISSO/ISSM.

Check Contents

Within the Administrator Console, navigate to the "User Manager" page under the "Security" menu. Review the roles assigned to each user against the ISSM approved list of user accounts and roles to determine if any user has excessive authorization.

If any user has roles assigned that are not approved by the ISSM, this is a finding.

Vulnerability Number

V-62353

Documentable

False

Rule Version

CF11-01-000007

Severity Override Guidance

Within the Administrator Console, navigate to the "User Manager" page under the "Security" menu. Review the roles assigned to each user against the ISSM approved list of user accounts and roles to determine if any user has excessive authorization.

If any user has roles assigned that are not approved by the ISSM, this is a finding.

Check Content Reference

M

Target Key

2661

Comments