{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cc746ce6-89ca-5f19-80bf-64474edb8d5d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-systests-databinding",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a2f0a417-e531-5d0c-a843-3e9de30c89f7",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0189d1bb-928b-5ed0-84ea-4bd5ec429bb5",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a7e0fd8-1220-551d-803f-0c39a87ddf44",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4eb2c475-3dff-51ac-9239-b9ffca31a75f",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90962ab4-3383-560d-bb7e-318b4f31ac36",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dd681dc-a42b-5262-964f-564f175e628b",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6385b9e-5496-52aa-a2f3-8c743f26555d",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fc2a0f4-dbfa-51a2-9854-d5881989d017",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5640f753-91e5-57b8-9332-9e6d35fa00db",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:665979d2-f54b-58fa-9487-9496069ac0e9",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:039e0725-16ec-5f8e-ba36-4ebb36ca0964",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:584d2617-ec9c-5698-8471-08db4674bad2",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b637576b-8eed-54fa-b460-1f951ee7c7a4",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db4559c-b384-5d3b-b9f5-d544f66a38fc",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef733d6-d1cf-5514-ab1b-30e38b987f37",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:776d8fb7-e96c-5ec6-bdbf-26026ab15c44",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6278028-93cd-51a0-9f93-0a81cf6cdc69",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.systests:cxf-systests-databinding 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd4f6be7-b5c2-50c1-9e5f-47e2d9ed00ef",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c6e754-a673-5bd8-abe4-24c0b823b42c",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c03bcec-f41b-519b-8931-2c6e9bd879f3",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58954789-d5ef-5fdd-a371-85cdc834af52",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8896baea-5946-5230-8a27-d8db14549f05",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93622498-8024-51e8-87ea-4238e205f69d",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3ce0fed-8d18-5ed6-bd86-3da6c98a1d2a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b51c1532-cdd6-5a41-8993-143061c4e49c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e56235a-c117-5324-80e4-6ed9f9b72d84",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.systests:cxf-systests-databinding 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64967447-5ed7-5af3-a352-7c7ee268de05",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf3abb5-6ed3-504a-82b3-2c132287283e",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c08a53c-cd99-54c4-856c-7efac28f5b47",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcf2fdd9-be3f-5a3f-993c-f7d78cff9980",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.systests:cxf-systests-databinding 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdc93145-42f7-5750-bf87-3cffb6b634fd",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0210fa5c-7aed-5dc7-9b57-80358ccb91cd",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91db2bd8-fa28-5ed5-9ca7-d6e49e33c19c",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a207f94-d58d-5a34-91d6-69a237020719",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf.systests:cxf-systests-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-databinding@3.5.9.tuxcare.1"
    }
  ]
}