{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a396722b-51ab-5be4-8663-3e5aaef0429a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf.karaf",
      "name": "cxf-karaf-commands",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7bcca47b-0d31-578b-ac90-5a2e43181d28",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fba3abe9-7279-5480-8fa1-25f1713d66a3",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95af292-fb3f-58b6-a694-73e0c7e84d9c",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:628e4515-8fe1-5373-8026-c4ed5504eca3",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ab4e33c-bc6b-5f7c-97cf-f7ba0c90b5dc",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:629255d7-46f6-5fe6-932d-1e31f483a712",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba0ef6c4-926e-54f0-be82-13d952f9d4cc",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a64b6574-e07b-5ed0-9263-637a8788189f",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d9e43b-7872-522a-8898-4bd404663cb5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6241bebd-9988-5154-a56b-568a4ae7c7b1",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c94b53f-5dc1-5d6a-8802-ad9ffc6daf47",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea8d224-a6ee-5c7e-8fff-9a5ec92550a4",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63ea537e-b16b-599b-81f5-89c636af2e29",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5e512e8-a6cf-5202-840e-8e44fb789cc7",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:082992e4-d5bf-5eb5-9a88-a6afcf20662a",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8330cc1e-d774-5148-a117-a314b7ad61c8",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30abe9b7-c054-57c5-b0e8-0f4e598ac21d",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.karaf:cxf-karaf-commands 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0fba9f2-78cc-57da-8411-117b167b4004",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9e6a23-8f4a-5700-9cb5-a2bd4280f6e2",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4831bd32-0037-5796-91b1-993f82554aff",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3174583d-64d3-56ac-a2f4-15aec0dd0268",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d15df43-a4cf-51d7-b05e-b937fe1cf698",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9db9aab1-51d6-5652-95a3-aa0d4f760976",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df4e90d0-a8d7-586d-a663-2f688bc9b084",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e0e904a-b835-5658-a4cf-d07e26856550",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fffe4992-17a0-5763-aa56-5dd52e29f73c",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.karaf:cxf-karaf-commands 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3840d30-f64d-5465-a5db-95669d2beb94",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84cd1b3e-78ff-5277-b330-9cbdf9c9d50f",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ebb740d-2604-55c2-aa3c-30dcfd82cb2a",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d59a92fb-c542-5ceb-93ff-aa4ae1375554",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.karaf:cxf-karaf-commands 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:086bcb79-5c4d-5847-98a8-67fc0734443e",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a72bfdc-c918-5769-9489-0acb5782c364",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:770d1a81-4bad-5cc6-a72d-fbaa266df8c8",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a0eb5a-07c2-5040-997b-c8b5a17d6632",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.3"
    }
  ]
}