{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:effcbf7f-422b-5e3e-9b4f-0e753728ad0c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf.services.xkms",
      "name": "cxf-services-xkms-client",
      "version": "3.5.11-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:03fc177e-2f20-5b08-828d-bcf867e3d72c",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1588c4a-2c3c-528c-aa5c-b42031c78e0f",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f3633ca-f53f-5da3-9b8a-3a70aa68bc3b",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe4f85f-1155-5568-a707-fecaf6c5bc8d",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581764cb-f5f1-566d-a40f-6e6ca2a83e53",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdd92c9a-859a-571f-8db2-d355f9d41276",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f7d89b4-a060-5fe4-8ffc-e1a72f7da3f4",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c73dfe5d-e2bc-5585-abff-1977e40f7aa1",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44ef293b-90bc-5a6d-8db9-146f7d29f6df",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc0d577e-57a9-5222-8040-f090b7ff3d99",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d70fb88a-8ebf-59cd-b07f-f6d1b33e9d14",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a557bd94-df21-51e4-b016-47b032644e9f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3052136-50b9-51a0-b520-1d0a3680b953",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d51f343-bdb7-56e4-8707-c0c3a8caf75d",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b32eec90-e4a0-5b29-b294-162fa48c116e",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75e214b4-e21a-52d4-9020-f3d745c07110",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17969fa-c376-548a-a353-03fca7ee8a56",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c45b21a-b3bd-55f9-9fc8-573c97dac11e",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f97af5f8-e7d3-5dd4-b9dc-140004b9b954",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f6049aa-cfff-572d-898e-6b88be661207",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae68324b-250a-5de3-8430-694c0bf78053",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06355d9f-e365-5885-9723-4e77a5320d5e",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b20c128-f401-50cc-9428-12d27934d4ed",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba02d162-2786-50bb-a7ae-5c82b05918b5",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc2134b3-0d96-5992-abdc-e38830fa9db1",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dbc5632-7ff2-5846-9a5c-86d4a7e51df5",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-client 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c4f497d-2047-5541-abd4-3c39bc30ab69",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f086c037-01d1-5487-9761-541abd5d24dc",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-client 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2c7190a-848b-5c54-abb6-ea756b6176ef",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72ef839c-4310-5755-a22f-2a3ddbf0bed3",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-client 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86205f71-d6ef-53c7-8ae8-3a42fccb66b1",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74c1899e-2547-5849-8958-87b683fb14ed",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-client."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-client@3.5.11-tuxcare.2"
    }
  ]
}