{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0bfa834f-1c13-5338-86f1-1685b75ae46f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf.services.sts.systests",
      "name": "cxf-services-sts-systests-advanced",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2673b75a-8af7-550f-943d-1fb07b720aae",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fcd7041-675b-59b4-a293-387e45231aa5",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30bfc7d-1c64-5d50-b63c-67eaf97d8e2d",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d1dac4e-5f00-534d-9715-aa66d141b6e4",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b64e3cf6-1d35-5dbe-90df-e3e45be4063a",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2600c911-ccc6-5fd2-bef2-4ba68d0f9469",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062be3d3-82c9-5455-b699-a578ef5455aa",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b5d6d32-29b7-58d0-8ab8-b76814c00efa",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c608f98-c2ae-5cd5-b481-9fc1387daaf1",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d71043bf-217f-53fe-a3c4-23c1c008e9f5",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d73c5ef5-5795-5b65-9f07-8eb20f09915d",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4af1e5df-5cfb-5f89-a1b3-b02fae2b13b8",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0da0f57-7eca-504b-b3b2-624c3d7d99f5",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dd995d6-df23-5eda-a791-10de76342e78",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4bc362-106f-5d67-94fb-b882b2bb0f50",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec50d7a9-a877-5edb-ac4e-2a9a421f8f9d",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b5718dd-8f59-5119-9df1-f31e42d54ac0",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28137a6d-73d6-57f0-b089-b54182aebcaf",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5fb3eaf-9643-59d1-a232-d9970d108988",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:636b437e-9cca-5f87-9e95-24d6c63e7631",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25012c68-43a7-5226-8de6-280df9d8d26b",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b88c0806-4204-5ac9-bd52-f9350995d58f",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e09d6929-2ba1-5504-85b6-72d84bcf5520",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df334528-d11f-59d3-a76b-7c9611d4ade5",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b6e8c8f-9359-5572-b093-27b91a78601e",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f44159d8-5465-57cc-908a-8e88edb742a4",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0cc8cc3-ac64-5876-999e-8e5c02e76103",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49e5b1e5-a16a-5141-9f68-692bdbfdb752",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb927753-5f79-59f1-b802-56f2a92b5038",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe3779d-4234-5e13-8cf5-5a558acfe441",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4115e4-5989-5d3c-8df4-da4f2b9bcf52",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18f03bfd-2044-55d1-8c1e-f69f4c396109",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.3"
    }
  ]
}