{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7136718b-6719-5d02-9099-bf5d0ed185e5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-systests-jaxrs",
      "version": "3.5.11-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:58716a9c-beba-56cc-85b6-c94e06bd2897",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b7b834-4505-51df-adcd-141a1f386887",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a43617fb-11f9-5e16-8f8c-519d13679a31",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97e9ff48-bcb8-5f62-bad9-4e60b304ebff",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b22b0c05-a761-54d2-82b9-554e58f021ea",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e978e13-e9e2-553f-816e-6f815d72f847",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9364aca-dc08-5c2a-b773-770f35f1e72f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f2dc904-36e4-5231-9dca-ed206f30a4e7",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61919fe9-b750-5792-8383-2821fd9f0a97",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:146d6e5f-927f-5156-ab5d-786704975bb0",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a968ec9-4d97-5798-9201-d686e8f4efcd",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cccf50d7-2d72-5366-89b9-aacb40d700dc",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99234f7b-fc74-5531-9ba2-5593005f3d63",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19df69d2-17f7-541d-b62a-57430c7d8a0d",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a4b2472-0ebc-5252-8ba8-6eb6b5b6b099",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8412bf8-456f-5d07-aad8-7fde307480bf",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e0618a4-8339-5f2f-b5dd-bda5e0f9b4f2",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf1b2ae9-160a-5cc6-a850-dc17322349f8",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d76897-4619-54bc-994a-cdd1fa524656",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ac6282-6247-547a-a9cc-ed7c0bbb8453",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59225fe7-bdb9-5692-8eb1-32d2f49cbd21",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:492aaa24-b0d4-5014-9281-396d075ae697",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:151d80dd-64e0-5eea-8856-d7089aa3061c",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e493af46-8e00-5050-9ea2-0f2492dff6f5",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2338e696-867b-52d7-bfbc-3f1b2d2aa7da",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55747411-0f51-5135-b7ce-c221145b083a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.systests:cxf-systests-jaxrs 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88810f44-9a53-514e-abf9-3d660138aed9",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:128affae-1f84-58b8-a85c-c68777d0a440",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.systests:cxf-systests-jaxrs 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2409b348-2214-59c0-a71d-f5605d26b208",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49ad33f9-6b97-55ef-9787-db3ecd8fc814",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.systests:cxf-systests-jaxrs 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9535cb4-fc32-5305-919b-1a19a48fc728",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb10a0fc-34bb-57d6-ab48-7911c36ee5c7",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.5 of org.apache.cxf.systests:cxf-systests-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-jaxrs@3.5.11-tuxcare.5"
    }
  ]
}