ColdFusion must have the CFSTAT feature disabled when not in use.
Overview
| Finding ID | Version | Rule ID | IA Controls | Severity |
| V-279052 | APAS-CF-000285 | SV-279052r1171523_rule | CCI-000381 | low |
| Description | ||||
| Application servers provide a myriad of differing processes, features, and functionalities. Some of these processes may be deemed to be unnecessary or too unsecure to run on a production DOD system. ColdFusion offers the CFSTAT command-line utility to retrieve real-time performance metrics for the system. This feature uses a socket connection to obtain the metrics which can also be used by an attacker to observe privileged information about the system and must be disabled if not in use. | ||||
| STIG | Date | |||
| Adobe ColdFusion Security Technical Implementation Guide | 2025-12-19 | |||
Details
Check Text (C-279052r1171523_chk)
Verify the CFSTAT feature.
From the Admin Console Landing Screen, navigate to Debug & Logging >> Debug Output Settings.
If CFSTAT is not in use and "Enable CFSTAT" is checked, this is a finding.
Fix Text (F-83505r1171361_fix)
Configure the CFSTAT feature.
1. From the Admin Console Landing Screen, navigate to Debug & Logging >> Debug Output Settings.
2. Uncheck "Enable CFSTAT".
3. Select "Submit Changes".