a product of
Foundeo Inc.
This report is for a ColdFusion 11 Server, see an example security report for ColdFusion 10 or ColdFusion 2016 or Lucee

ColdFusion Server Security Report [example.com]

Do you know this much about your ColdFusion server? - Subscribe for $10/month
ColdFusion Version: 11,0,03,292480
Operating System: Linux x86_64
Web Server: Apache
Server Local IP: 192.168.1.13
Probe API Version: 1.4
Java JVM: 1.7.0_51 Oracle Corporation running as root
JEE Server: Apache Tomcat/7.0.52
Hotfix Jars: empty.txt
Cumulative Hotfixes: warning ColdFusion 11.0.12 / Cumulative Security Hotfix (Apr 25, 2017) Not Installed
warning ColdFusion 11.0.11 / Cumulative Hotfix (Dec 20, 2016) Not Installed
warning ColdFusion 11.0.10 / Cumulative Security Hotfix (Aug 30, 2016) Not Installed
warning ColdFusion 11.0.9 / Cumulative Security Hotfix (June 14, 2016) Not Installed
warning ColdFusion 11.0.8 / Cumulative Security Hotfix (May 10, 2016) Not Installed
warning ColdFusion 11.0.7 / Cumulative Security Hotfix (Nov 17, 2015) Not Installed
warning ColdFusion 11.0.6 / Cumulative Security Hotfix (Aug 27, 2015) Not Installed
warning ColdFusion 11.0.5 / Cumulative Security Hotfix (Apr 14, 2015) Not Installed
warning ColdFusion 11.0.4 / Cumulative Hotfix (Feb 19, 2015) Not Installed
check ColdFusion 11.0.3 / Cumulative Security Hotfix (Dec 9, 2014) Installed
check ColdFusion 11.0.2 / Cumulative Security Hotfix (Oct 14, 2014) Installed
check ColdFusion 11.0.1 / Cumulative Hotfix (Sept 22, 2014) Installed

Please note, Cumulative Hotfixes focus on bug fixes and may or may not include security hotfixes, they are not required and Adobe may only recommend installing them if you are experiencing one of the issues resolved (please read the linked KB article).

TLS / SSL Report

Common Name: check www.example.com
Certificate Expiration Date:
check November 5, 2017 (3 months)
Public Key Size:check 2048 (2048 or greater recommended)
Signature Algorithm: check sha256WithRSAEncryption
Certificate TrustStore Validation: check Mozilla NSS 09/2016: ok
check Microsoft 09/2016: ok
check Android 7.0.0 r1: ok
check Apple OS X 10.11.6: ok
check Java 7 Update 79: ok
Contains Anchor Certificate: check No
Valid Chain Order: check Yes
Protocol Support: check SSLv2 Disabled
(SSLv2 should be disabled, it has been considered weak for over 10 years and has been disabled in browsers by default since IE7)
warn SSLv3 Enabled
Preferred Cipher Suite: AES128-SHA (128 bit keysize) HTTP 200 OK
(SSLv3 should be disabled, it has been considered weak since October 2014 due to the Poodle Vulnerability. Disabling may cause compatibility issues with IE on Windows XP, and old android clients)
warn TLSv1 Enabled
Preferred Cipher Suite: ECDHE-RSA-AES256-SHA (256 bit keysize) HTTP 200 OK
(TLSv1 may be enabled for existing implementations, however PCI DSS 3.1 April 2015 ยง 2.2.3 states that: SSL and early TLS are not considered strong cryptography and cannot be used as a security control after June 30, 2016 2018 (date changed) . Prior to this date, existing implementations that use SSL and/or early TLS must have a formal Risk Mitigation and Migration Plan in place. Effective immediately, new implementations must not use SSL or early TLS. Disabling TLS 1.0 may cause compatibility issues in Internet Explorer, see TLS Browser Support Chart.)
check TLSv1.1 Enabled
Preferred Cipher Suite: ECDHE-RSA-AES256-SHA (256 bit keysize) HTTP 200 OK
(TLS 1.1 may be considered an early TLS with respect to PCI DSS 3.1 compliance. Talk to your QSA for details.)
check TLSv1.2 Enabled
Preferred Cipher Suite: ECDHE-RSA-AES256-GCM-SHA384 (256 bit keysize) HTTP 200 OK
(TLS 1.2 should be enabled)
Compression Supported:check No (Compression should be disabled due to CRIME)
Heartbleed: check Not Vulnerable
Logjam: warn 1024 bit DH Group Using a common prime! (a unique 2028 bit DH group is recommended More Info)
Session Renegotiation: check Client Initiated Session Renegotiation Disabled
check Secure Session Renegotiation Supported
OpenSSL CCS Injection check Not Vulnerable More Info
Strict Transport Security warn Not Enabled More Info

We found 14 security issues on your server example.com

critical
SSL Version 2 Enabled
Your Web Server is accepting SSL V2 connections, a weak protocol. For PCI compliance, and strong security you must disable this protocol on your web server.
More Information: http://foundeo.com/products/iis-weak-ssl-ciphers/
critical
Robust Exception Information is Enabled
Robust Exception Information is enabled which leads to path disclosure and partial source code disclosure
critical
AdminAPI Exposed to the Public
The /CFIDE/adminapi/ directory is open to the public it should be locked down to prevent exploit.
important
ColdFusion Administrator is Public
ColdFusion Administrator should be restricted by IP or blocked with Web Server password protection. Also consider requiring a SSL connection.
More Information: http://www.petefreitag.com/item/750.cfm
important
CFTOKEN is not a UUID
CFTOKEN should be set to use a UUID in the ColdFusion Administrator. Session ids may be very easy to guess if UUID's are not used.
important
RDS may be Enabled
RDS may be enabled on your server (due to a change in recent CF versions we can no longer detect if it is on or off, however we have detected that the RDSServlet URI is responding to requests). We recommened that you block the URI /CFIDE/main/ide.cfm and/or remove the Servlet Mapping in web.xml to prevent unnecessary access to the RDSServlet.
important
Certificate Signature Uses SHA1
Your SSL Certificate is signed using a SHA1 signature, which is considered weak. You may see security errors or warnings in Chrome.
More Information: http://googleonlinesecurity.blogspot.com/2014/09/gradually-sunsetting-sha-1.html
important
SSL Version 3 Enabled
Your Web Server is accepting SSL V3 connections, vulnerabile to the POODLE (CVE-2014-3566) attack. Consider disabling this protocol, which may impact old clients such as IE6 on Windows XP. Disabling SSLv3 may also impact server side HTTPS clients (that consume your web services or APIs), and potentially bots / crawlers. You can use our IIS SSL tool to disable SSLv3 on IIS: https://foundeo.com/products/iis-weak-ssl-ciphers/
More Information: https://poodle.io
important
The JVM is Running under Privileged User Account
The JVM process is running under a system administrative account (eg SYSTEM, Administrator, or root). ColdFusion should be running under an un-privileged user account.
important
Tomcat 7 Vulnerability
The version of Tomcat 7 you are running contains security vulnerabilities that are fixed in Tomcat Version 7.0.78 or greater.
More Information: https://tomcat.apache.org/security-7.html
warning
Session Cookies are not marked HTTPOnly
Using HTTPOnly cookies prevents the session cookies from being hijacked via a javascript XSS attack on modern browsers.
More Information: http://www.petefreitag.com/item/764.cfm
warning
LogJam: DH Group Uses a common prime.
Your HTTPS server is configured to use a common 1024bit prime. Security researchers estimate that a nation-state could break encryption on servers with a common 1024 bit DH group prime.
More Information: https://weakdh.org/
warning
LogJam: DH Group Smaller than 2048 Supported
Your server supports a DH Group Size smaller than 2048 bits. It is recommended to use a unique 2048-bit Diffie-Hellman group. Note that Java 1.7 and below cannot connect to servers (eg with CFHTTP) using a DH group size larger than 1024.
More Information: https://weakdh.org/
warning
SSL Certificate Public Key Below 2048 Bits
Your SSL certificate public key is below 2048 bits, consider making a new certificate signing request (CSR) and rekey your certificate with 2048 bit key or larger.

Please note, this tool is not able to test for all potential security issues that may exist.

Dig Deeper & Stay Updated with Our Paid Service

When you Signup for our service you can:

Pricing starts at $10/month

Severity Key

Critical
Found 3 Critical Issues
These issues pose a significant security risk. It is imperative that they are resolved at once.

Important
Found 7 Important Issues
These issues may have a security risk in certain conditions. It is recommended that you resolve them.

Warning
Found 4 Warnings
You should consider fixing these issues, however, they do not pose a large risk.

See a List of ColdFusion Security Vulnerabilities detected by this tool.