CVE-2016-2016: HP Base-Vxfs-50

Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.

Affected products

  • HP Base-Vxfs-50: version b.05.00.01 only; version b.05.00.02 only
  • HP Base-Vxfs-501: version b.05.01.0 only; version b.05.01.01 only; version b.05.01.03 only
  • HP Base-Vxfs-51: version b.05.10.00 only; version b.05.10.02 only

Published 2016-05-14. Last modified 2026-06-17.