{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8cc32e00-a222-5ac7-a77d-724c9cd1a612",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6",
      "type": "library",
      "group": "org.apache.cxf.services",
      "name": "cxf-services",
      "version": "3.5.11-tuxcare.6",
      "purl": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a0737d44-c353-5e3a-82e1-082b8cd5379a",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:367c7abd-e1b3-5716-8ca7-24991a358d1a",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f4b6ae-11a3-5a23-adcd-dac8131f6135",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e143aa71-ecfd-5216-8bbb-d94787cea256",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915f4c20-0205-54a7-9693-c32daa325dce",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e9a2f3-e7d1-5725-9d7a-23eb1a0abc96",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:276e228d-f6bc-5408-a682-a8b6bd8b64e7",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a4c3ae5-5066-59f8-974b-5cd23d5b465a",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5691f9b-9779-5f78-b74b-b2af5f3ea51f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97b0ca18-aa81-5446-8a25-58a6cbde31d3",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb6cb536-54f4-5efa-b193-d208de1df5e4",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:913b0d2b-669b-54a5-aca0-8fe6664dcd24",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffff42c-b866-5ecf-a620-5ec4f458a4ee",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d5dd964-8c58-56b3-857d-817349a55a87",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:822267f4-0f43-5db2-b662-438fda63634c",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f056e4-1827-50d9-b772-b044482a38cf",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc100a60-2238-5d7c-b2d2-8b267fd33694",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1814b953-5240-5e08-a4f7-543914f7edaa",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2c341a0-bd81-5536-adaa-bd263e871572",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cf3b4c6-4cba-506d-8de7-78144bd56809",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea1e1d15-79eb-5868-ae46-9bc152536111",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4d58c8b-3eec-59d2-9dce-5d4f07441bf6",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31ff4070-829b-5618-87eb-50787dbf4e4e",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a015174c-3246-58ef-90ca-3eb65269e637",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427f1969-60bc-577d-9cb5-db74ab5043bb",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f325bba0-830a-5d29-8ce8-d9486783ea32",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services:cxf-services 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bf24f2a-c290-55fd-b3f0-f730203437a7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0734011-b6fa-5ee3-bfc8-66bd6e280e6c",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.services:cxf-services 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95c128e9-d7d9-5913-a22e-6bf495583a8c",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aec71ce-b7e4-5fa2-8908-18c85bc4d1b0",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services:cxf-services 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16e33a02-3eb5-5363-9bb9-dcb0a896c532",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbe7889-37aa-5412-a157-a7579254e1e5",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.6 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.11-tuxcare.6"
    }
  ]
}