CVE-2022-23675: Arubanetworks Clearpass Policy Manager

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A remote authenticated stored cross-site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

Affected products

  • Arubanetworks Clearpass Policy Manager: up to and including 6.7.14; from 6.8.0, before 6.8.9 (fixed in 6.8.9); from 6.9.0, up to and including 6.9.9; from 6.10.0, up to and including 6.10.4; version 6.8.9 only

Published 2022-05-17. Last modified 2026-06-17.