{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:158a9d15-ee5c-5f57-befb-68e6e0da2acc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.karaf",
      "name": "karaf-parent",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e97083b6-8952-52c6-a305-6e8249608102",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e324514-929c-501e-ba2b-ac918876df09",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e7d3e68-067a-5bd3-9f1a-b75b9b834bc6",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:667343ec-c727-5919-952d-51312725d537",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aee63fd0-6e93-582d-b494-ad76cec59538",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:869547aa-8257-5e85-aa1b-383a2f9047a7",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a06f90b2-c284-50ae-95bc-7aa1dbf76376",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:206d7b8a-db50-5720-a392-cbd8b7b0b95d",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf6a0ee-6ad5-5f10-bfd5-a9bf79973f97",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4e18f8b-608b-5360-8472-3a7ee8b5fb45",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff085de0-ad6a-59fb-80a4-73756942b3fd",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085174aa-d1a6-5e81-8dfe-c8ecd49f928b",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeb274c8-77dd-5978-97b8-c3d6cc6406b5",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5007358-a844-5d13-a6b6-a9fb154445a3",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f566f98-a4ba-5cba-aca8-70d4959d407b",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1c2e3b8-092a-5d4f-b084-a28994185777",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:878ea7a0-88e9-5e62-925f-f6d90f95d5f5",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27762219-1168-5303-a839-adda70b6e7d1",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39889d50-8efb-523f-92b1-33d73da57baf",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ae3aa76-0334-51a3-a4ad-a2134a00723e",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fac0c4d5-1f76-5bec-b1e5-ad76183b05e9",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1cba905-06d7-5b76-8d71-065f002b3971",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:359d3755-639d-5b6d-9857-664691333338",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc289150-ffff-5826-8102-176866da93b7",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:255ba6da-5d16-5628-8016-2d872bdb3e69",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e676784-eaac-5e1c-8ea0-271a6ce2194f",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.karaf:karaf-parent 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f3176ff-62e8-5638-93d4-cc6112100e43",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67efd1c1-55fc-527e-b296-c4953f2c2750",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.karaf:karaf-parent 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd00298c-069e-5f72-8c4f-eba33a1d4257",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0c3000-69f1-57c8-9bcc-68b676caac5b",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.karaf:karaf-parent 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9291a81-af4e-5651-b97c-09a42fdbfafb",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8a6fb4b-bd05-56b6-8e0c-81c321f5f377",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.1"
    }
  ]
}