{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:474e3634-e47b-55c7-9a2c-d8f9e0a34435",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.services.sts",
      "name": "cxf-services-sts-core",
      "version": "3.5.11-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e8985821-76fe-512b-b1b0-72cc2907eabf",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec48004d-5265-5503-9667-985ae1b27e9e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:537c711e-2627-57c3-8919-802d7529d87f",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05aa77ec-1304-5805-af75-305e80a3cff9",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26e8658c-a075-5640-8f47-df7ed8de85ee",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b4567cd-af03-5d92-9ed9-0f591c022972",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc039bfa-c333-5c00-b48c-7d212ce5e746",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4eaf2b-37f1-572e-b4fd-2b981d8d1dde",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:596d7e72-aa8f-5946-9dec-8e3eb0ebc92d",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef954b18-984c-5a2a-a917-2b87c2cb33ef",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92bbe53b-a201-5552-a38d-fba9f2e810ef",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e94d0000-816e-52f2-9aa7-117f38e476d9",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:983ee5d6-16b1-5186-a29b-9cc3bcfdbd43",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:739c4a0f-bbfc-5a14-9a80-7a861b5497df",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b60ed0db-a8ad-555f-8645-37b78b0c0527",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9066e057-588f-52ea-8c13-ad0a8acd56ac",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8d8ffd1-96f2-5e55-9197-2e86ebc005a1",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ac557b-09f1-5b7d-a7bb-e53c70fac347",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5189bd6-2752-54d5-9c95-d4ba3319ed1c",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e3245cb-e3d6-581c-ae75-2bc6b926a79e",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63bfbc95-9eb4-5cd0-a4e3-3313fdf4a04b",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4738ce31-109f-5df6-b470-0384de6129fb",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:541278b4-1b86-5594-88bb-e48505f11990",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e17be1c-346a-51c6-91d9-fd5122a05b93",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4008b8a-cf30-50c0-ae61-92ea911c750d",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b97cdc5c-bed7-581b-a0c7-6cbf6893f48a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts:cxf-services-sts-core 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee9e527d-d6dd-5a2e-a6a8-f974ba55feda",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca5e948-2c30-5b61-8b67-42e29a0371eb",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.sts:cxf-services-sts-core 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114f50a0-448d-5fb2-93f7-88fd756ce6a4",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21a055d3-5ec0-5513-baa9-d7c28d410b10",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts:cxf-services-sts-core 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e400876-9049-5fbc-8bee-c53a7b5a5c2c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73cf7936-2657-57c5-a86c-e4b4a9b5da1d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.5 of org.apache.cxf.services.sts:cxf-services-sts-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-core@3.5.11-tuxcare.5"
    }
  ]
}