Check: CF11-02-000049
Adobe ColdFusion 11 STIG:
CF11-02-000049
(in versions v2 r1 through v1 r2)
Title
The ColdFusion log information must be protected from any type of unauthorized read access through the Administrator Console. (Cat II impact)
Discussion
Allowing any user to view log messages provides information to individuals that may be used to compromise the system. This information may provide system design, user access/IP addresses, interconnected systems, and security settings such as encryption used and version numbers. Controlling read access to this data, either through the Administrator Console or through the OS, must be controlled or limited to only those individuals who need access to fulfill their responsibilities.
Check Content
Review the roles assigned to the defined users within the "User Manager" page under the "Security" menu. Only users given the responsibility to read logs should have the following role assigned: Debugging and Logging>Logging If any user, other than those assigned to read logs, is assigned this role, this is a finding.
Fix Text
Enable the Debugging and Logging>Logging role for those users that require the ability to read log files. This parameter is set in the "User Manager" page under the "Security" menu.
Additional Identifiers
Rule ID: SV-237151r641548_rule
Vulnerability ID: V-237151
Group Title: SRG-APP-000118-AS-000078
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000162 |
Protect audit information from unauthorized access. |
Controls
Number | Title |
---|---|
AU-9 |
Protection of Audit Information |