
46
4.1.6 Update Java Virtual Machine
The Java Virtual Machine included with the ColdFusion installer may not be the latest JVM supported by
Adobe ColdFusion 10, or it may contain security issues. Download the JVM from java.oracle.com.
4.1.7 Block Unused file types
ColdFusion provides a number of capabilities that are not used commonly which can be blocked. A good
example of this is JSP file execution. Here is a list of file extensions that ColdFusion handles by default:
File Extensions that
usually
can be blocked (check with developers first):
Purpose
Safe to Block
Executes CFML templates
(same as .cfm files)
The .cfml file is not typically used by
developers, if you don’t use .cfml block this file
extension.
JavaServer Pages
Yes, if your applications do not require JSP.
Java Web Services - allows you
to easily write and deploy SOAP
web services in Java similar to a
CFC.
Yes if not used.
Hybernate XML mappings
Yes this should be blocked.
A more robust solution is to specify a whitelist of allowed file extensions, and block the rest. For example allow
only .cfm .css .js .png .html .jpg and block anything else. Your application may require additional extensions.
Summary of Contents for 38043740 - ColdFusion Standard - Mac
Page 5: ...5 ...
Page 12: ...12 Next Click Add Roles and select the checkbox next to Web Server IIS ...
Page 26: ...26 ...
Page 33: ...33 ...
Page 38: ...38 ...