{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d96600b5-d9bb-52bd-a5d9-413278efac46",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.services.xkms",
      "name": "cxf-services-xkms",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:70aa1bf1-3c4f-5f0a-b58d-9b9a40961565",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8d04d07-1d1c-5f48-a07b-30750aecc920",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4bab78b-9c75-5545-9a93-a8875846112a",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8a9e1b8-7736-5830-a986-c070741708b1",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c04cb7-5a03-546b-abae-bfd327e9abbf",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:671edbc8-c06a-5c6e-aba8-71827712cb8f",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2b8b33e-c811-5fb6-b443-d00c53694675",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4526151c-fbe1-5f8c-b97e-4a95d8205726",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ad074fa-b863-5a47-9963-ee0a1e91fe0e",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a49e174-4bac-5a9b-934c-7046a7924329",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89694fe0-e2f2-544a-b95e-c30f5947b03c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:663f5ae3-7075-5438-bd5b-22129328c377",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:668f3af8-aa2f-5f63-9f0a-920b62f577be",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e58f02a-ff72-5802-b14a-56c0c2210d94",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:512be8ac-838f-5e83-a9bf-19619fd3a299",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13eadd28-5062-5323-a027-d4daa1533912",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a143e6a-384d-5ff5-88d9-a0e222b80f07",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d04788-7486-5e16-be44-f6206ddc9aa9",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86980003-529b-52d3-9cb5-0668eb28bc8e",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbe1ec9c-6c32-57cf-be19-a3312c0b5848",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7462d6ec-3871-59b5-b907-e97f047e6336",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47661219-c8a3-5bf1-82dd-17d08724ad6a",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df1c62d0-7049-5f55-b65a-fb4271cdfe54",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89db1a0f-ba27-58bc-8efa-583fc20bf5d7",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4093d600-c331-5b03-a7e8-78e4b3bee1c3",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaca02c0-c68d-5086-910e-cee67a96e8ad",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed08d1fd-e8b5-5d0b-bb0c-33423a5a276a",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:355bc35f-38d2-5666-9892-8fd2162d6751",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63bff690-8239-5d31-848a-c516d687fa00",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16ac1363-724e-59ac-ae96-90fb67f976e3",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e2ab36e-6529-50de-a5fe-2ae73e624b78",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:babd81a0-7033-519f-a939-a1f0d5d7d387",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf.services.xkms:cxf-services-xkms."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms@3.5.11-tuxcare.1"
    }
  ]
}