{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:38385e86-c7b6-5472-84f4-5681b5391507",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf.karaf",
      "name": "karaf-parent",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:03160f4d-de25-5fdb-8913-43fc33a283fb",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79d3eabf-b1d8-5273-b009-171f3abac1a0",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbff5e4a-d335-575c-be96-9a91fd1074e5",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b24c6994-8fbb-58b7-b627-9c64c197a29d",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf85ed9b-9588-58d6-a7fd-c704b6f3f7a7",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7846404-0680-5a05-a965-668f77392cd4",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:827b6b47-287d-5dc8-8bbb-5aa03da9eb6c",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bad1320-b183-53fa-867d-467b24d9dd1e",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cd223cc-c32f-5b00-8792-fa0ff181493a",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cbc8d5d-80bb-5b56-a762-25518d8e8b7d",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3805fd00-a48c-5c8f-aec9-001d788b1158",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a65d34d-7e5b-57c0-9c45-6ce0204ead2f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6643e593-a9d0-5a1d-99a9-38d8917fb10c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5673c040-dc31-585f-86bd-82af30537ca3",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:941e7e73-b07c-5bd2-9615-40baf33e1b08",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d967e88d-028a-5002-9986-e5336df8638c",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:309b6724-e3fc-5d09-bdaa-65ace6694f2b",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ce69768-c1a0-5942-8a98-d341885fcf64",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f557815f-8d38-51bf-be4e-4b721dc13a18",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6304786-15c0-5381-b3af-8bb902a6d002",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cc23cd5-5310-53c5-b187-0edc5d1219f0",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede5a986-1a39-5969-96f3-a14e45ebf324",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:087ad3c8-435b-53dd-b44c-ac85264f7082",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8479ecb0-97fa-59b9-b0a5-d981fe5cb0c0",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a0b113a-b78e-59a2-93f8-5e630732b0f3",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:732db526-ff49-5031-bb49-6e6b42433d30",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.karaf:karaf-parent 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4421f78-a331-5d27-88f1-efe2d2641a84",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e4e79c2-ef7f-5ca6-89b9-555632ad132c",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.karaf:karaf-parent 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae6cfd65-ac01-59fd-8b8e-7dc4669d083c",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:261980c4-f77f-5644-a853-a3d69d67378a",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.karaf:karaf-parent 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a071ab76-8dbe-5e80-aad2-683a5ba1b0c5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7b80d99-fc63-50fa-85d2-d772ecb97b3c",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf.karaf:karaf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.karaf/karaf-parent@3.5.11-tuxcare.3"
    }
  ]
}