Security Advisory
CVE-2014-1996
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Cybozu Garoon 3.7 before SP4 allows remote authenticated users to bypass intended access restrictions, and execute arbitrary code or cause a denial of service, via an API call.