{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cf7829f9-687d-5249-bba6-279d437b0231",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.services.wsn",
      "name": "cxf-services-wsn-osgi",
      "version": "3.5.11-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0dac413d-4877-5adb-b49e-5dc2f04d6a98",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58c44cf1-0322-5b7d-b9e0-7e83175968f6",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed0fdf18-f272-59af-90de-c796282de26e",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a34fe057-29ef-565f-9e01-af8be59d0059",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:420ffc6c-cf8f-58b5-a542-11bef7e6b3cf",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c931a682-8583-577a-bd41-1595badda3c1",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca6ed39d-f45e-52bb-a535-6145a23ba43f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81dd1a96-22a3-5c11-80ca-f427c1606983",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cda0f35-b6a9-5560-bcb9-6613e6d1e229",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:387f3c9b-b15c-519b-a997-dda0ffc5f781",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d72caf9d-f945-53a4-b0c4-6512dfe895df",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe82c353-8642-5c8b-8d27-97bc21ef4fb1",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90e3724a-2a6a-570f-9c5b-fc9862dde277",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b499f28-120d-5839-ad0f-48fc957a7c87",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc2f669-ac98-5ab9-9b7b-c69b4bb91c0c",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24da4a2e-156f-59af-80e7-46a6e458d0f2",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db4aeafe-f371-5f97-86b8-6f618fcd8d07",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63f35d97-b6ad-5cb1-8f5e-3dab8d4e162c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06ad6a10-8b58-504b-be19-938253a46790",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c024d01-18b1-5c2b-ac5c-bfff0c79a1c0",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:389e8b9f-0730-5b91-ad63-dc2388707469",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aed5443-f392-5b73-8288-acfbdb11597f",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cea9b45-c866-5cdf-8520-c2f42fc465f6",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1684e26b-030d-5842-9616-abc699031247",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b91a83-9548-54a8-ad5b-0231153f6e5b",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaaa4423-1e2a-5ef0-b559-e22d75a6dbdf",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.wsn:cxf-services-wsn-osgi 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f61c5427-1d54-57a0-bb82-c186c4d550f3",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae160800-5188-57df-85b1-9706f4219226",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.wsn:cxf-services-wsn-osgi 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb1b97d1-7036-5320-80f8-9b74c503c9b8",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f8790ec-0565-5a8c-956f-acfcf14b1ef5",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.wsn:cxf-services-wsn-osgi 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b986fa-456b-598b-936b-32cf0fb4ad5b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bda91b89-799e-5212-9736-4f4492ddf5cf",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.5 of org.apache.cxf.services.wsn:cxf-services-wsn-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.wsn/cxf-services-wsn-osgi@3.5.11-tuxcare.5"
    }
  ]
}