Check: CF11-05-000162
Adobe ColdFusion 11 STIG:
CF11-05-000162
(in versions v2 r1 through v1 r2)
Title
The ColdFusion Administrator Console must be hosted in a management sandbox. (Cat II impact)
Discussion
ColdFusion consists of the Administrator Console and hosted applications. By separating the Administrator Console from hosted applications, the user must authenticate as a privileged user to the Administrator Console before being presented with management functionality. This prevents non-privileged users from having visibility to functions not available to the user. By limiting visibility, a compromised non-privileged account does not offer information to the attacker to functionality and information needed to further the attack on the application server. By hosting the Administrator Console within its own sandbox from other hosted applications, the administrative objects are protected from reuse and modification by the other hosted applications.
Check Content
Within the Administrator Console, navigate to the "Sandbox Security" page under the "Security" menu. If the Administrator Console is not hosted within a sandbox, this is a finding.
Fix Text
Navigate to the "Sandbox Security" page under the "Security" menu. Create sandbox for the Administrator Console to operate within and select the "Submit Changes" button.
Additional Identifiers
Rule ID: SV-237196r641683_rule
Vulnerability ID: V-237196
Group Title: SRG-APP-000211-AS-000146
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001082 |
Separate user functionality, including user interface services, from system management functionality. |
Controls
Number | Title |
---|---|
SC-2 |
Application Partitioning |