5.5

CVE-2016-2016

Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HpBase-vxfs-50 Versionb.05.00.01
   HpHp-ux Version11.11i Updatev3
HpBase-vxfs-50 Versionb.05.00.02
   HpHp-ux Version11.11i Updatev3
HpBase-vxfs-501 Versionb.05.01.0
   HpHp-ux Version11.11i Updatev3
HpBase-vxfs-501 Versionb.05.01.01
   HpHp-ux Version11.11i Updatev3
HpBase-vxfs-501 Versionb.05.01.03
   HpHp-ux Version11.11i Updatev3
HpBase-vxfs-51 Versionb.05.10.00
   HpHp-ux Version11.11i Updatev3
HpBase-vxfs-51 Versionb.05.10.02
   HpHp-ux Version11.11i Updatev3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.166
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.