{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:da9bb73a-7004-5ed8-9cb4-8b4de90eb3eb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-systests-tracing",
      "version": "3.5.11-tuxcare.6",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:56d719ff-7686-510a-bfc9-26e768012a1a",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f76936-21d7-5e15-a27b-c87174a0fa0a",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85d84b34-4d03-529e-9e6f-3a93a3dba1ee",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5aea876-9097-5cba-8e09-71f2cb4b9de6",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:173dec34-9746-5ca8-ad62-1c9fdeb51fbb",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4999d89c-8c4f-562e-86e8-8a4007d5c12a",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ad8c54e-dbc1-5adc-849a-6d9e0031ef3f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21cfeadb-2944-5b81-b889-52e55cc0ff7b",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bca4f4b1-9001-5837-aa88-5f9e51f5781a",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b0c1dda-a82a-5aee-8748-d66dce3bd899",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6da11da-e482-5d5e-89dd-0c58216f432a",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80c7c8da-f12f-5637-9105-e753ae4caf86",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82f632d1-c635-5f9e-9d97-ea26332edc96",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30656e94-f7b6-5185-94ba-abb2e3430d9b",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e1ca3ad-8090-5f03-a2da-9501567d74c1",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf0ed0a6-0ecb-5d3a-a304-53d3588ca589",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a80c012f-f086-5374-ad32-f9c5774f975a",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f305199f-d8be-599f-b5b8-42ef7b0ab518",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8357f2c-7d6c-5fb6-81fd-d1b35b139154",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b70505b1-0ea9-57a0-91e0-b54e3ba4d1e6",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:895358dc-1e80-50de-b560-f9c310ac09ae",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcddc7a8-007c-5756-a9f6-2c7fa683efb5",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d01b4a30-f057-5356-a0fc-ab49dddd0f44",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e8b11a4-825f-5d1d-ba85-5cc48ee9005f",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba2a796d-1e38-5507-ad3c-001b24388cfd",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b62a3ba-48e4-5e14-ad96-a00a88a9b30b",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.systests:cxf-systests-tracing 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52e0d75a-4ae8-5a6b-80aa-9ca1f090ab4e",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ed1ef86-4349-5129-a03a-b84eb720421a",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.systests:cxf-systests-tracing 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7f15b4e-9919-5011-be85-f5a456a9abb4",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11e138e8-10f0-52dd-8cfe-c1620b4bc469",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.systests:cxf-systests-tracing 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85634dfd-7304-5d3f-964a-83ccb1d1f435",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4362a08e-cdad-538e-9b9d-e01c2ac2e164",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.6 of org.apache.cxf.systests:cxf-systests-tracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-systests-tracing@3.5.11-tuxcare.6"
    }
  ]
}