A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in ‘/var/backup/tower’ are left world-readable. These files include both the SECRET_KEY and the database backup. Any user with access to the Tower server, and knowledge of when a backup is run, could retrieve every credential stored in Tower. Access to data is the highest threat with this vulnerability.
CWE-732
CVE-2019-19363
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print – Version 4.0 or later PS Driver for Universal Print – Version 4.0 or later PC FAX Generic Driver – All versions Generic PCL5 Driver – All versions RPCS Driver – All versions PostScript3 Driver – All versions PCL6 (PCL XL) Driver – All versions RPCS Raster Driver – All version
CVE-2019-19315
NLSSRV32.EXE in Nalpeiron Licensing Service 7.3.4.0, as used with Nitro PDF and other products, allows Elevation of Privilege via the \.mailslotnlsX86ccMailslot mailslot.
CVE-2019-19262
GitLab Enterprise Edition (EE) 11.9 and later through 12.5 has Insecure Permissions.
CVE-2019-19263
GitLab Enterprise Edition (EE) 8.2 and later through 12.5 has Insecure Permissions.
CVE-2019-19218
BMC Control-M/Agent 7.0.00.000 has Insecure Password Storage.