CVE-2025-6056: Ergon Informatik AG Airlock Iam

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows unauthenticated attackers to enumerate usernames.

Affected products

  • Ergon Informatik AG Airlock Iam: from 7.7.9, up to and including 7.7.10; version 8.0.8 only; version 8.1.7 only; version 8.2.4 only; version 8.3.1 only

Published 2025-07-04. Last modified 2026-06-17.