{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c79bec3f-d856-5acf-97cd-9de148bd7f6a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf.services.sts.systests",
      "name": "cxf-services-sts-systests-advanced",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9b2ba91e-bd23-565a-8eab-8a314fe413e2",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3e820f1-024e-5b5e-aed9-3aa7f60378c9",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28ab3f6c-b139-5f9b-b000-279e5bec13ad",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e4d522e-662e-5248-862c-fd457c7a87a3",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aed348a-9e56-546b-82be-6c8bb58590d6",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38f2dd80-bc90-572b-bebe-b2378961fe7a",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e6f9480-b4ff-5f98-bc47-daf5e1555486",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74d1abf0-1df2-5e00-b379-b212c7c4a138",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe19870-7c89-54ea-bbe8-491334031405",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88d5e0df-fe1c-5680-9b38-11f2cb061cf5",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59f272c4-680b-5a51-a572-88780e991fa8",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981e3f7c-887a-52b8-a89a-8853133c9954",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fdd4f4d-84f4-56cf-9775-11fe9d00bff2",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5117265-6780-5f4d-8a2a-600b62f7bdb7",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:263b2bc9-c613-581c-b47a-e336077c6ae0",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:355c787b-97e6-5286-b4b0-9f99d4ab83c9",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b9520d-75fd-5915-a4b0-1e20c3832aaf",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea3272a-cf0b-5c77-9174-48547071fd57",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:149a0c5b-efe5-567c-be4f-914bf3ffdeeb",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22af1d68-8467-5a3a-9d0a-8e2f6e2db094",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f84bbb1c-5828-5b3f-9dd5-a9136d289b77",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34dbd693-869c-50a4-b710-e67581341c15",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1e94b1b-5ffe-51fb-b94f-5a84b30f2cb6",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dea48e41-85fe-5ed5-bd59-cfd59fd48850",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b867d34-5c8f-51f9-8f0b-d6a64b68944f",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62234efe-0451-538a-ba01-a997642cbef0",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6883da77-baeb-5729-b5ac-4eec45d5aa86",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81264fd1-f793-5ae0-a789-73a9ed262758",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92d0f0a-ed1d-5a27-9f18-08377a5f9f4b",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f1abdf8-9301-51b1-8e8b-ec49d1a0e6bc",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1c19309-0a9b-5142-9d0e-c73744bfec8b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:866ccf45-a122-51c0-a57b-25b6cd5e55a8",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.11-tuxcare.4"
    }
  ]
}