{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1d12e38e-9c54-522e-962d-d792c7d3815c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6",
      "type": "library",
      "group": "org.apache.cxf.services.sts",
      "name": "cxf-services-sts-systests",
      "version": "3.5.11-tuxcare.6",
      "purl": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0e3b4e3a-2ead-50fb-a1b9-f2c4145fd00f",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dc11869-9192-5125-81c5-f0ffe289d836",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:637b3b56-30ef-528d-acbb-850178ec33a7",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a95bb1a6-3356-59b6-aab6-2089acda0105",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4c52d34-bf6f-5011-8fe8-195a04c28d8e",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29c08f74-c6aa-5f53-9f8a-94674b8ad0e4",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a92c1db-7b0d-532e-8591-9f9767a2e805",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:529624fa-c0cb-53b3-9ac9-5f63fa382183",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4adc969d-fbc7-561d-9c3d-f19a4977cca8",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:766a71e3-b3ad-5d3e-9f36-186d7ec4fa1a",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc9c03fb-d84d-5ae3-b84a-e5dd3bd1f550",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:230d4e76-7507-5de0-a303-d418a8947c55",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bb0055e-bb31-571f-85e0-203e8a52d6c0",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:407fbd66-6631-5e21-81f4-8dfb146e137c",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:949c1f37-64e8-520c-983b-1b5b43ed6801",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bfbf91a-0602-5f13-a761-2ef17b266c27",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:180bfc1e-86c3-506b-9d86-08b37f478b91",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eab10d2-48b2-5d95-909c-055d4184686b",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05af9f02-2408-518a-8c05-89e48616fa04",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49b1a998-fa2d-5eae-a1c8-9715dbd4d25c",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d655f8f3-ed32-56b6-94ef-70d350ae3fb9",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db8e92ae-31c4-5ab8-82db-7a88a4b9b18a",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0030746e-33c0-53f1-8792-9d5a564e8da2",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ce9e109-b3c5-5d23-800d-cbe41264ccb9",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e1d85a-d5ac-5ae9-92d4-09f182549cf4",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69048e8d-34c5-554c-b494-14da4c7f3ca6",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts:cxf-services-sts-systests 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae5fa811-6415-59fb-a8e9-d61f1640fdea",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48cff33c-1423-5b85-9787-812f87dfacfb",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.sts:cxf-services-sts-systests 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15870edc-cd65-58f5-b6ae-41bc9bc469af",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d33165-f741-59c0-bb18-40797d9c9ca4",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts:cxf-services-sts-systests 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ced95a8-a57c-531c-8c2a-e7e185725047",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98508b5-b9cd-5daf-a85c-919700123a8a",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.6 of org.apache.cxf.services.sts:cxf-services-sts-systests."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts/cxf-services-sts-systests@3.5.11-tuxcare.6"
    }
  ]
}