Exit
  • Global community
    • Language:
      • Deutsch
      • English
      • EspaƱol
      • FranƧais
      • PortuguĆŖs
  • ę—„ęœ¬čŖžć‚³ćƒŸćƒ„ćƒ‹ćƒ†ć‚£
  • ķ•œźµ­ ģ»¤ė®¤ė‹ˆķ‹°
0

Is there any hope in a new STIG to support newest ColdFusion

Explorer ,
Apr 28, 2023 Apr 28, 2023

While its vulnerabilities are still mostly relevant towards newer versions of ColdFusion, DISA has now sunset the Adobe ColdFusion 11 STIG as it has not seen an update since 26 Jul 2021. Is there any hope at all for Adobe to work through the vendor STIG process for the newest iterations of the software? 

Reference: https://public.cyber.mil/stigs/downloads/
Reference: https://public.cyber.mil/stigs/vendor-process/

691
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Apr 30, 2023 Apr 30, 2023

You are asking about Adobe working through the vendor STIG process for the newest iterations of which ColdFusion version?  

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Apr 30, 2023 Apr 30, 2023

Indeed, and I will add that I'd brought this to Adobe's attention directly the other day, and asked them to please offer some answer here. 


/Charlie (troubleshooter, carehart. org)
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Jul 13, 2023 Jul 13, 2023

@BKBK , I apologize for the great delay. I forgot that I put this out there. Yes, I am asking if Adobe has plans to go through the vendor STIG process for newer iterations of ColdFusion. 

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Expert ,
Jul 13, 2023 Jul 13, 2023

I have no idea. But I would guess not. It's a lot of work! Adobe ColdFusion contains a bunch of bundled products that Adobe doesn't completely control: a modified version of Apache Tomcat, a modified version of Apache Solr, DataDirect JDBC drivers, a bunch of JARs, a server JVM, and so on. So why should they go through that if they don't have to? My guess was that they did it back for CF 10 or whatever and decided there wasn't any benefit for them.

 

Dave Watts, Eidolon LLC 

Dave Watts, Eidolon LLC
Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Community Beginner ,
May 01, 2023 May 01, 2023

Adobe has a history of responding to security vulnerabilities in their products and releasing updates to address them. It's possible that they will work through the vendor STIG process for their newest iterations of ColdFusion, but this would depend on their internal priorities and resources.

In the meantime, organizations using ColdFusion should continue to follow best practices for securing their systems, including keeping up with security updates and patches, monitoring for potential security threats, and implementing appropriate access controls and other security measures.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
Aug 13, 2024 Aug 13, 2024

I have heard (unofficially) that Adobe is currently working on updating ColdFusion STIG and are targeting Q4 2024 for release.  No info on which version this will cover, but presumably 2021 and/or 2023.

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Explorer ,
May 13, 2025 May 13, 2025
LATEST

This is still unofficial, however my organization received this from our Adobe support contact earlier this year: "We are awaiting review comments from DISA on our final [STIG] submission.  Once 2023 is closed, we can look to get one started for 2025.  Since there are not too many changes in 2025, that should be straightforward in my opinion."

 

So it sounds like they're targeting CF 2023 for the next STIG publication.  Last update was early-April - team still waiting on DISA review.  Hope that helps!

Translate
Report
Community guidelines
Be kind and respectful, give credit to the original source of content, and search for duplicates before posting. Learn more
community guidelines
Resources