Check: CF11-05-000161
Adobe ColdFusion 11 STIG:
CF11-05-000161
(in versions v2 r1 through v1 r2)
Title
The ColdFusion Administrator Console must be hosted on a management network. (Cat II impact)
Discussion
ColdFusion consists of the Administrator Console and hosted applications. By separating the Administrator Console from hosted applications, the user must authenticate as a privileged user to the Administrator Console before being presented with management functionality. This prevents non-privileged users from having visibility to functions not available to the user. By limiting visibility, a compromised non-privileged account does not offer information to the attacker to functionality and information needed to further the attack on the application server. By hosting the Administrator Console on a management-only network, the console is protected from hosted application users, is isolated to only management devices, is not vulnerable to accidental discovery, and most management networks encrypt all traffic protecting management data from accidental disclosure.
Check Content
Access the Administrator Console through a browser making note of the IP address that is used to access the console. Review the site's network diagram to validate that the IP used is on a management network and is separate from the public network. If the Administrator Console is not part of a management network, this is a finding.
Fix Text
Host the ColdFusion Administrator Console on a management network.
Additional Identifiers
Rule ID: SV-237195r641680_rule
Vulnerability ID: V-237195
Group Title: SRG-APP-000211-AS-000146
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001082 |
Separate user functionality, including user interface services, from system management functionality. |
Controls
Number | Title |
---|---|
SC-2 |
Application Partitioning |