{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fa1551a6-2cce-5b9d-813c-36cd2ba963ca",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf.services",
      "name": "cxf-services",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f5e891d4-70a3-5653-9e1a-bedf7231ccb7",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce19a964-6da8-5c0b-b56a-9c04d6c741b6",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173236b9-8f7e-5dbc-83fb-38f664329743",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cbd70e7-03a2-5cb2-a509-029adee51df6",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be050865-1ef7-504d-86ea-3ae507f658e1",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9464617f-d67f-56f4-b7e5-bb130533e3d9",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5081557c-4f97-59c1-a28e-77430580eabc",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d8b3529-0117-535e-a776-605fae917849",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13e41c4e-d3bf-5ac4-ad5a-04d62b81830f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ecd9abe-d660-5cc1-9b38-de010c008789",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8608acaf-4356-50d8-abdf-89516294c89c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c507eaa9-5d99-5a6f-acbd-0eb1ee638144",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8915c314-0246-5556-81de-841e1a813cec",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a4855a-163d-51b6-98df-3eb1e923de8e",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75cb3130-df4c-5483-9b12-07d62a9a90b0",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:828d8312-2b14-5a0c-84ac-6247e1303c2c",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8726ea53-79c9-5405-b945-6d1f390bd620",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services:cxf-services 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43bc6da1-f630-5b67-9ca7-03efeecef7aa",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8addec8-d82b-5170-a95a-22789ad1a557",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0959ffaf-93e9-57ec-ae55-019b87c47297",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41eae78c-d4f7-585c-813e-456d60c2938d",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab07e2c-9737-5d40-b7fe-b13bcf068f89",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e3efb65-30b5-5d20-91c6-a124a7098a47",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78093f49-c633-5710-9ecc-d27c16085f47",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf210480-de2d-506b-8418-b3047448fea0",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:995aa07d-6a0b-53be-83eb-e3ad26e51247",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services:cxf-services 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac681653-a5f3-54cd-a3e1-3db0c0df8596",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a047218b-8f28-54d0-8428-312e31fdb249",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:670d9a40-c34c-5f98-abea-0d30d0757bb0",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e300ea91-0d48-571f-af01-eadfbbcd5e5e",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services:cxf-services 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a50c4703-fcd7-56f1-b776-07b241c4e859",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a66c711-c3eb-5629-b8c3-6d9f1b796ebf",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39e922dc-79cd-5741-9749-06282213bad4",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dcdc44f-f59a-5fce-a9a8-8bb4c64a8282",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.3"
    }
  ]
}