{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:83b2c7ff-be90-5d2a-ab56-aea8dd3461cd",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf.services.sts.systests",
      "name": "cxf-services-sts-systests-advanced",
      "version": "3.5.9-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5462fb6c-5b59-540e-a881-609650224550",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32d8593c-cbd6-5d46-9381-e7b3236d37f7",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c82c396d-04b0-5b70-88c0-838605306268",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91bbf466-4289-5cbf-9ff2-a02adea55cfb",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa0e5db6-ae7f-5e78-a730-cbef64f03586",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e459ce08-ccef-530b-8465-a7cadc2176d7",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a36f12-efdc-5cb7-aacf-cabe46dc139d",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b1ef7ba-5c1d-56ec-93a0-eeda45179d13",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:248c3aaf-0f7d-5b63-830a-5ccc68e836c5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b057aaa6-3fe4-59b2-af16-389b5390b303",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e2e250-8f58-558b-b698-07a4917ec2fa",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3bc6c25-e4ca-5bce-9cce-0396d3f6f0ec",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:145ce3b1-94d7-5428-a0d7-f8a220a81226",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:949d0b0c-0ae5-526d-943e-748e460a4a14",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1664383-ae00-53a4-aa36-4ed47d6aed15",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:644ff087-65a7-5b27-b331-0a35f702440f",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3d422b-2a68-51b7-823d-6b26576c198d",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40fce623-60df-5674-afeb-00892ee8976c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f2e0929-e127-526c-bd9b-4af058c00f12",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6d3be9d-b62c-5ec4-8495-100af780418f",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fe2033-dac4-5567-bb53-53f3508d9f77",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6bd7dfc-4214-5829-98d3-b3cc6d0deec3",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a710a09-643d-5b4b-a86a-e0ed1a39f9d2",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d21e816-eee8-5b45-af59-b520fb31c640",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4dcf42c-194b-5026-823c-5b90457e04e1",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07bf16a2-04b4-555a-9956-40c78aaec1f0",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3feb1d6e-a72c-5fee-8f44-063391d7984b",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac0e2cee-0b12-57cf-8e02-2a6b2dd2de65",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7715118c-c5ad-5cea-99d4-bc045203c1e4",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:849f7bda-afb0-5914-b769-4451b26405ae",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:281cd16e-8d81-564b-b8aa-5f06991e834b",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71fb4e76-dac3-5509-bfdf-34f5723ffa87",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebb9519e-3aa7-5a2a-a8c1-91103491af24",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcb6bf0b-bf2a-54f6-a950-8a594cf34c9e",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.4"
    }
  ]
}