Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-11689: Are the Centrify products affected by Speakup backdoor CVEs CVE-2012-0874, CVE-2010-1871, JBoss AS 3/4/5/6, CVE-2017-10271, CVE-2018-2894, Hadoop YARN ResourceManager, CVE-2016-3088?

Auditing and Monitoring Service ,   Authentication Service ,   DirectSecure ,   Privileged Access Service ,   PC Auditing and Monitoring Service ,   Privilege Elevation Service ,   Smart Card Service ,  

7 February,19 at 12:26 AM


Are the Centrify products affected by the following CVEs which are associated with the Linux backdoor named SpeakUp?

•    CVE-2012-0874: JBoss Enterprise Application Platform Multiple Security Bypass Vulnerabilities
•    CVE-2010-1871: JBoss Seam Framework remote code execution
•    JBoss AS 3/4/5/6: Remote Command Execution
•    CVE-2017-10271: Oracle WebLogic wls-wsat Component Deserialization RCE
•    CVE-2018-2894: Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware.
•    Hadoop YARN ResourceManager - Command Execution
•    CVE-2016-3088: Apache ActiveMQ Fileserver File Upload Remote Code Execution Vulnerability.

External link to CVE documentation:

Centrify Infrastructure Services (previously known as Centrify Server Suite)  is not affected by these CVEs as they are all for web applications.
The Centrify Privileged Access Service (PAS) is based on Internet Information Services (IIS) so it is also not affected by these CVEs