{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f970b4c5-af5c-56c2-a333-a20587621c53",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf.services.xkms",
      "name": "cxf-services-xkms-war",
      "version": "3.5.11-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b286b635-99eb-5316-8272-2b5a32bda451",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73aa9df6-8d68-54cd-a3da-57d8ba58f531",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70f9d024-8b81-57fa-9b0f-f1144f5356d1",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13889fdd-b0c9-593d-9c03-4f1914a45b24",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f50e41-c2ed-5b24-8400-908422ffe530",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32e80eb7-66e4-57d2-afe7-2e90f392613c",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62c4059c-a842-5660-98a6-f0eed986a1bd",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:693c4478-bb8a-5bc0-b5a3-e9bdf4acf9c8",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16ec1fdd-f766-551b-ab01-9fbd659f498d",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:175e28ba-07f3-56bf-838d-db176522f204",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3ebec8c-76ce-515d-b430-a27d50a51728",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e253a3f1-4222-5c4a-8db0-25254bcefe30",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57ddb28e-fed3-5b6e-bf11-ccff502834c8",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a9171c-7b08-5c31-a697-6f3caa69bad3",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e222b275-630f-554d-af25-fd953586f1dc",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13ad0cd0-3de1-5a3a-bc21-49f50cd77c29",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89916c01-662d-5780-b0be-1d9278a818dd",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa772341-1a26-5d29-951c-c12b014f59bc",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67a00b20-49ba-5504-aff3-a8e1aae47e97",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3f07e54-9401-522d-9e57-3e5acd0a0e01",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f400fe3-6269-5e9d-870e-ad06af1973af",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc679303-e9b5-502c-9a4e-ebc158c97415",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fab97fb-1e42-55ec-a415-190fd468d5f2",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be57ef35-e57e-5369-8092-ab40e6865078",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:022ab924-2935-510c-a589-4fec9217b2bc",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd9615e9-c0e2-57a6-a18e-e857d3b37421",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-war 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:226d7c53-560f-594c-82cc-407e86186035",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f78c17b7-c0b3-569b-b154-23ad657d76da",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-war 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ee6188-88cd-584d-841f-08c9731af39a",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80896d64-290d-5e76-9f7f-d80a464b4abc",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-war 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d4478f-8e7f-5982-b203-fa9bf41949d5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c87e9a1-ab5c-51d2-acae-74afe892298c",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.2 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.11-tuxcare.2"
    }
  ]
}