{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:84da21e9-74d4-570b-86dc-b30eca1a2162",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-microprofile-tck",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fcf0ad55-f82d-5460-81d9-48b927a269e5",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eabf3b07-3b7c-5357-9b84-93b333d361f8",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0044e89-988f-57af-80f8-0513e658836f",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa80412c-bd37-57f5-967f-656e9c6b0784",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:650d7e97-d271-560f-808c-420a26510383",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2b20fa1-05d1-5e44-8a52-13c1a0372e10",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69442926-905e-5ae6-b568-42eada1b7156",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acdf37a7-7a14-583d-b65c-bf524102489b",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88662034-9a59-5a05-a7a3-4e4377f5eaa7",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a8b65e8-9241-59f0-8561-fcfe52825b89",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c688396-3033-5d70-ad5d-b407f8ed9bc3",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf2ad57-6d2d-5a17-9953-ac63b0281a03",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36996dc3-956f-540f-9a2b-6d2c046a1678",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e473e2d9-235a-5ffb-b42c-eb6364a709c0",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2687c7e-8b57-53cd-9a6f-6dbdf17f8b39",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bed49a96-09a6-5f61-abe6-825e3e9231d4",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2646688f-39e9-5c6f-bfa9-6fa295e15cd0",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d808c92-f2a1-54b8-980e-bbc6b81494ed",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e1f54d9-f7a2-527a-a72c-3c422295c9ee",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d91c56-6a2c-5d3a-a53e-411a86655c8f",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ff64b86-c111-58ff-9d7a-2f2c030025ce",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c743f0f8-1da1-50d7-9205-b9ec5f696f33",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d615a1e-d0ea-5385-b95f-20d176922417",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:896e552d-0364-5402-bd14-8c53b8e490b8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54455e6e-5ee4-5eb1-9286-0cc319afea7d",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be39440f-b0e5-5c91-b840-8054c8c0ae1f",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.systests:cxf-microprofile-tck 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b83c902-20df-5d4d-b7be-c603b6cd7a2a",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62b8f369-beb2-578f-8a50-193476d7f671",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.systests:cxf-microprofile-tck 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a05a034-e097-53d0-9ac5-c9bdd3141316",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c730b914-1300-5257-970a-17da2c2e600d",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.systests:cxf-microprofile-tck 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cce6a82-7916-565e-b787-7bb285491595",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b3b9c2-459e-5ea3-832c-7d4a2954c094",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.4"
    }
  ]
}