NYU's vulnerability profile centers on its OpenSSO integration product, a specialized identity and access management component deployed within academic and institutional environments. The observed weakness classes reflect web application input handling, with cross-site scripting vulnerabilities being the primary signal in the durable exposure pattern. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nyu over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-7293MEDIUM Cross-site scripting (XSS) vulnerability in the logon page in NYU OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory Services (PDS) allows remote attackers to injec | Jan 2, 2015 | 4.3 | 18 | NO | NO |
CVE-2014-7294MEDIUM Open redirect vulnerability in the logon page in NYU OpenSSO Integration 2.1 and earlier for Ex Libris Patron Directory Services (PDS) allows remote attackers to redirect users to | Jan 2, 2015 | 5.8 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nyu.
Media articles that mention a CVE ID that affects a product developed by Nyu — matched by CVE ID, not by vendor name.