{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe38c00f-dbc5-5834-8971-fbebac9a75f0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.services.xkms",
      "name": "cxf-services-xkms-war",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ee1a0555-c5f8-5af5-9ffe-0a6916a453c6",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02382aef-13cc-5ff7-a44c-7354eca822f0",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19b0a11e-56b4-55ab-bfdc-a12a2145be26",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e893c1f1-95a2-5fb6-83ea-144c9fd2c28f",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ff9520-4b85-513c-95a2-16388275f05b",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba6478bf-9194-5a18-88a3-6ed6a7d0b45f",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:821b6950-d9f1-5b2d-a993-3261c8bf261f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:878bc3e1-cd55-58c4-b967-b1f8acb1d1cf",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23d05e74-1960-55f9-982f-40cd504d8470",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3263cc8c-c9eb-52f0-9a36-aef54a53a142",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ca22dee-3e86-57d1-9e24-839c64737a32",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5682b52b-d37a-5670-9129-58c5ea32bc6e",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:236ba39b-246e-5d62-bd67-c124d380b8c5",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69966c33-ea08-550b-bce8-816089e015e5",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c9265fa-597b-578f-9806-2331d0341500",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84708026-12c8-513b-98ec-760ea1fac7fa",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00920a01-6e83-5a43-b4a6-3b95d80aa747",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-war 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30920c46-b9f8-557a-a418-8d932207f028",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88fce6ce-2174-5918-8db2-478ce4a3d65e",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38d4c24f-e04d-55e4-835f-47dc92c01530",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2c51d26-1f0f-5e68-a7bd-7def42c291c5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53c556ea-50f0-58d0-9966-b131ac78de42",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a03c65ea-55af-5784-9967-dd7232362b5b",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a6005b-f91b-557f-9932-30354082d139",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b39609f-c463-53e8-95de-60df2d65dab8",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de7a21d-e800-59e6-9af2-2e1a1e55a7d4",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-war 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2484748-afa2-5130-bebd-42e5b4702bb7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d73025a-f1bb-59eb-ae5f-836b148cd548",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c29c938-de21-50d3-b481-e96f701a2dec",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff98319-a745-5ad7-8be7-1f5da8dce052",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-war 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c29f06b3-0293-5ffd-b4a1-96a2e7057f26",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9417bbe-041f-54e1-8a36-84fd5eb3edb8",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a76df90-6474-51f3-882a-ba0acdf27cb0",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad6b0d8-1b1d-58f8-9d0f-44b65eff5bbb",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms-war."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-war@3.5.9.tuxcare.1"
    }
  ]
}