{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1989df8d-f066-521a-9083-4a70be436770",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf.karaf",
      "name": "cxf-karaf-commands",
      "version": "3.5.9-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ce275588-16c4-5876-ba71-b523b144fffd",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cedb3be8-8ce5-523f-80f3-f6d067add35f",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b97010b-81c2-5522-8308-d87ee5704123",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1623b45-4018-5169-a221-5911a042d0f5",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9424a493-14af-5af2-89a5-c3a35b422efc",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e95e4f4-c9c7-56f1-9b43-df0fed002a45",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98ee2014-7e60-5705-a2b1-8e3be49ce484",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:342078bd-e57d-53c3-9720-e780a0d8c1c7",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2710b9e6-8fd2-5aa9-bd27-44417be6f946",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b90f7ec1-1406-52a1-9571-18bbfb655ca8",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9db2e72f-70dd-5527-8d7d-9d5c52d3524f",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dfc0526-3b6c-516e-a39f-852fdcbf7b3c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66e513d3-070c-5c65-87c3-330422efa618",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7cdbd5e-ce43-53ee-9322-126f4954342f",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:871e6d5a-41aa-53bb-a298-b02fe3ee16fb",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02ddf979-5930-5ec4-a327-d0d6ede378b9",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e840cf9-d710-5be6-9885-e2dd2dcc6546",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.karaf:cxf-karaf-commands 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbb8225c-f9c3-58cc-b6ff-6137db445f8c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b1a2ba7-ca08-5ccd-874c-72710f281bc7",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64f46af6-d73e-5454-ae07-f3f14ef5c6d3",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f052462-751c-5a62-9a81-1feb6ba31cd2",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b0d08de-be4a-5f54-8767-4cb08be5b8ea",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d71d3251-f305-5d47-9cef-b67b4026711b",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad953688-70a2-50af-b5ca-cf135839b92a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae4fe96c-0fc8-5149-964a-d8e742f885ac",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:577ce979-f59c-5329-8e60-833510ec389c",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.karaf:cxf-karaf-commands 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cbb0303-c646-50fe-b086-82466bd41ef7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea18176d-ca10-591f-83e4-a279e8de5b95",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:656e927e-0d51-5e1e-97db-211ce59ec676",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64e4ba32-469b-551f-a65c-c4404c433166",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.karaf:cxf-karaf-commands 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a70f570-9138-5bd3-b53c-de1b9c254c4c",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d117462a-5ec1-5261-98f6-16fb2f680732",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f4b8052-141c-51ba-acd5-5495c2ab543c",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc22be22-c34f-5c7c-961d-effeaa8ea752",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf.karaf:cxf-karaf-commands."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.karaf/cxf-karaf-commands@3.5.9-tuxcare.4"
    }
  ]
}