{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b10ab18c-ed91-5a47-9ede-e8626119212a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf.osgi.itests",
      "name": "org.apache.cxf.osgi.itests-felix",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:41bba0c8-94c9-563f-8c9e-500e2bbd4719",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b41dcbe7-1cfe-5c41-bc38-bc8cee0c4cd8",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba846252-9f47-525c-aa63-26b41c26340a",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72b61f3-9ff9-5e6b-b501-5595aedd2c90",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb64ff6c-e4ef-59a8-aacb-a98cc4f5d5d0",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10207c88-b51a-53f1-8f41-e60818a83669",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0121a1d0-52ad-5c1a-ab7c-101d13576edd",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1230321-2da4-534b-9b1d-de506f9b6b91",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a46f1dcd-2b56-5cf6-9d97-75c37629d365",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38962ffd-9073-585a-afb1-9a0f819b207e",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b5d3b76-8a4d-55be-aa70-490e7882ab80",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:130e3e03-2bbb-5a98-b60d-1e7b0dbee134",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a23f0f9-4996-5fc5-b1e8-02d5ce871a9c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a39579a-51bf-542c-8b95-676f5df93721",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f3e16f-1dfa-5b82-9ad7-5eb7d750f322",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ee9e30-14e2-5ad6-be52-f0dacc9f358f",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19aed0fb-0432-5c11-bfed-3670ead78738",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b16c7f7-c5fb-5e35-ad8c-407d030d467b",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7092ee42-8c79-5dc7-aaae-83eb05056060",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24d95683-0a81-59cb-9e79-6147f8b947aa",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4029b5cd-4724-5596-8c0c-0cd0e61834f5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa93e296-7e8f-5e48-85cb-15052ab0cc12",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:157f42ba-71a4-558a-958d-9d4d4b37f3b9",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9886cd78-ab84-5b3e-ae84-352b6dfe4ffd",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7138677-25bd-5c77-b110-99dbdd3b7866",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e505252-b47b-5cf8-81ed-08290634133c",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bad78950-2512-565e-8e0f-70cde00c50a7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eb4cb99-4a19-5c70-930d-e4065e46ccf4",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0372793a-e1ef-5c61-9e6c-50fbbbdd4494",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2edcd7c0-fb12-5444-948d-1e871dae6a3b",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75156829-b87c-5978-b222-8f04d397f94d",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ea7bed0-a830-5f1e-a27d-ae2baf0d3405",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.11-tuxcare.3"
    }
  ]
}