a product of
Foundeo Inc.
This report is for a Lucee CFML Server, see also an example Railo report or an example security report for ColdFusion 2021
Want Lucee server security reports? HackMyCF starts at $10/month
  • Automatically scans your server on a daily, weekly, monthly or quarterly basis
  • Get Notified when Lucee, Tomcat, Java, CommandBox, etc. need updates
  • Daily, Weekly, Monthly or Quarterly email report with info like below about your servers.

Lucee Server Security Report [example.com]

Lucee Version:
Operating System: UNIX Linux amd64 2.6.32-042stab063.2 i686
Web Server: nginx/1.2.5
Server Local IP:
Probe API Version: 1.9
Java JVM: 11.0.7 Oracle Corporation running as root
JEE Server: WildFly / Undertow - 1.4.24.Final
CommandBox: 5.1.0 (Runwar Version: 4.3.0)

TLS / SSL Report

Common Name: check www.example.com
Certificate Expiration Date:
warn November 7, 2017 (Expired!)
Public Key Size: warn 1024 (2048 or greater recommended)
Signature Algorithm: warn sha1WithRSAEncryption (SHA1 signatures are considered weak and may cause warnings or errors in Chrome)
Protocol Support: check SSLv2 Disabled
(SSLv2 should be disabled, it has been considered weak for over 10 years and has been disabled in browsers by default since IE7)
warn SSLv3 Enabled
Preferred Cipher Suite: AES128-SHA (128 bit keysize) HTTP 200 OK
(SSLv3 should be disabled, it has been considered weak since October 2014 due to the Poodle Vulnerability. Disabling may cause compatibility issues with IE on Windows XP, and old android clients)
warn TLSv1 Enabled
Preferred Cipher Suite: ECDHE-RSA-AES256-SHA (256 bit keysize) HTTP 200 OK
(Disabling TLSv1 is Recommended, see TLS Browser Support Chart)
warn TLSv1.1 Enabled
Preferred Cipher Suite: ECDHE-RSA-AES256-SHA (256 bit keysize) HTTP 200 OK
(TLS 1.1 may be considered an early TLS with respect to PCI DSS 3.1 compliance. Talk to your QSA for details.)
check TLSv1.2 Enabled
Preferred Cipher Suite: ECDHE-RSA-AES256-GCM-SHA384 (256 bit keysize) HTTP 200 OK
(TLS 1.2 should be enabled if TLS 1.3 is not)
Compression Supported:check No (Compression should be disabled due to CRIME)
Heartbleed: check Not Vulnerable
Logjam: warn 1024 bit DH Group Using a common prime! (a unique 2028 bit DH group is recommended More Info)
Session Renegotiation: check Client Initiated Session Renegotiation Disabled
check Secure Session Renegotiation Supported

We found 20 security issues on your server example.com

SSL Version 2 Enabled
Your Web Server is accepting SSL V2 connections, a weak protocol. For PCI compliance, and strong security you must disable this protocol on your web server.
More Information: http://foundeo.com/products/iis-weak-ssl-ciphers/
Lucee JSON Vulnerability LDEV-992
A vulnerability in the deserializeJSON and isJSON functions allow for information disclosure. Fixed in Lucee,,,
More Information: http://lucee.org/blog/new-security-patch-available-for-lucee-4-5-and-5-0.html
Robust Exception Information is Enabled
Robust Exception Information is enabled which leads to path disclosure and partial source code disclosure
More Information: http://www.petefreitag.com/item/752.cfm
Lucee Server Vulnerability 2023-01
The version of Lucee you are running is vulnerable to a security issue: CVE-2023-38693. Lucee 5.4 users should update to version or greater, Lucee 5.3 users should update to or greater, Lucee 6 users should update to Lucee 6.0.0.? or greater. For Lucee users running 5.3.7 through 5.3.9 following versions have also been patched:,,
More Information: https://dev.lucee.org/t/lucee-critical-security-alert-august-15th-2023-cve-2023-38693/12893/1
The JVM is Running under Privileged User Account
The JVM process is running under a system administrative account (eg SYSTEM, Administrator, or root). ColdFusion should be running under an un-privileged user account.
Java 11 Security Update Available
The JVM that you are running contains security vulnerabilities that could be exploited in server side environments. Update to the latest version of Java 11. Note that Oracle Java 11 requires a commercial license. Adobe CF customers can download Oracle Java 11 from the ColdFusion Downloads Page. You can also use OpenJDK, Amazon Corretto, or other non-oracle JVMs for free.
More Information: https://www.petefreitag.com/item/860.cfm
Lucee Administrator is Public
Lucee Administrator should be restricted by IP or blocked with Web Server password protection. Also consider requiring a SSL connection.
More Information: http://www.petefreitag.com/item/715.cfm
Lucee Docs are Public
Your website is serving docs for lucee at /lucee/doc.cfm or /lucee/doc/index.cfm allow only necessary requests under the /lucee/ URI
More Information: http://www.petefreitag.com/item/715.cfm
Lucee Security Issue 2015-10-20
Lucee fixed an XSS vulnerability in the default error and debug templates. This issue is fixed in Lucee and
More Information: http://lucee.org/blog/new-lucee-security-patch-available.html
Lucee Server Vulnerability 2020-01
The version of Lucee you are running is vulnerable to a security issue. Please update to version,, or greater. According to LAS 'If your Lucee Admin is already locked down, this is not an issue'.
More Information: https://dev.lucee.org/t/lucee-vulnerability-alert-november-2020/7643
CommandBox Vulnerability 2020-01
The version of CommandBox you are running is vulnerable to a security issue. Please update to CommandBox version 5.2.0 or greater.
More Information: https://www.ortussolutions.com/blog/commandbox-520-released
CommandBox Vulnerability 2021-01
The version of CommandBox you are running is vulnerable to a security issue. Please update to CommandBox version 5.4.2 or greater.
More Information: https://www.ortussolutions.com/blog/commandbox-542-released
Undertow Vulnerability
The version of Undertow you are running contains known security vulnerabilities. Undertow is a JEE Servlet engine most commonly used in CFML with CommandBox. To update Undertow make sure you are running the latest version of CommandBox.
More Information: https://stack.watch/product/redhat/undertow/
Certificate Signature Uses SHA1
Your SSL Certificate is signed using a SHA1 signature, which is considered weak. You may see security errors or warnings in Chrome.
More Information: http://googleonlinesecurity.blogspot.com/2014/09/gradually-sunsetting-sha-1.html
SSL Version 3 Enabled
Your Web Server is accepting SSL V3 connections, vulnerabile to the POODLE (CVE-2014-3566) attack. Consider disabling this protocol, which may impact old clients such as IE6 on Windows XP. Disabling SSLv3 may also impact server side HTTPS clients (that consume your web services or APIs), and potentially bots / crawlers. You can use our IIS SSL tool to disable SSLv3 on IIS: https://foundeo.com/products/iis-weak-ssl-ciphers/
More Information: https://poodle.io
Session Cookies are not marked HTTPOnly
Using HTTPOnly cookies prevents the session cookies from being hijacked via a javascript XSS attack on modern browsers.
More Information: http://www.petefreitag.com/item/764.cfm
Lucee Server Context is Public
The URI /lucee-server/ is open to the public and should be blocked.
More Information: http://www.petefreitag.com/item/715.cfm
LogJam: DH Group Uses a common prime.
Your HTTPS server is configured to use a common 1024bit prime. Security researchers estimate that a nation-state could break encryption on servers with a common 1024 bit DH group prime.
More Information: https://weakdh.org/
LogJam: DH Group Smaller than 2048 Supported
Your server supports a DH Group Size smaller than 2048 bits. It is recommended to use a unique 2048-bit Diffie-Hellman group. Note that Java 1.7 and below cannot connect to servers (eg with CFHTTP) using a DH group size larger than 1024.
More Information: https://weakdh.org/
SSL Certificate Public Key Below 2048 Bits
Your SSL certificate public key is below 2048 bits, consider making a new certificate signing request (CSR) and rekey your certificate with 2048 bit key or larger.

Please note, this tool is not able to test for all potential security issues that may exist.

Dig Deeper & Stay Updated with Our Paid Service

When you Signup for our service you can:

Pricing starts at $10/month

Severity Key

Found 4 Critical Issues
These issues pose a significant security risk. It is imperative that they are resolved at once.

Found 11 Important Issues
These issues may have a security risk in certain conditions. It is recommended that you resolve them.

Found 5 Warnings
You should consider fixing these issues, however, they do not pose a large risk.

Scan ID:

See a full List of Lucee & ColdFusion Security Vulnerabilities detected by this tool.