{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5f09d48f-f9b3-5839-a253-224aa01a8d66",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-bundle-parent",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2fa10139-57d6-5a54-96ef-05ca9a70b989",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed332444-106b-5b9d-8197-d28b788528de",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e502ca2c-5c38-5b02-855f-f14077a7fbb1",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce073878-d08b-5305-a0df-45344ab6d0de",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4175fe3c-f655-5bf6-854b-0b6b5c063639",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b95edd14-9655-5d0e-8107-3999fcac603a",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb89ff15-9c34-5d63-a6e7-1d01e803b81a",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14ba8dba-1780-51bf-ad07-ef1af90b689e",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c35695b3-01de-559b-93a8-161adaa47c32",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dec2fe88-b7e5-5536-a276-4cb9364756df",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79f00338-ea91-56a3-bcde-a96a2f4dbde7",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f38b611-d78c-5ba0-aec8-222d5daab260",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c22aa42-f6fd-5f8a-b9dc-24ef4feb57b1",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:236dd1d7-2e98-56b9-b262-51ed43f904a6",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe77130-12f8-58dd-9977-10ef0f400b0c",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:961021d3-440a-54fc-96dc-d0bacf31795e",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1b08443-611d-5b0a-9cb1-2ee813bbb9d5",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-bundle-parent 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdbfae4c-3dd8-579a-a285-c85456abd3ed",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8be898db-e4e1-5115-b734-f98942b92499",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81fa4c5b-083c-5578-84b0-7fb541a39c67",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:405bddbd-cebd-5469-8332-bc924dd8df5f",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db5f9179-2602-5faf-90fc-27fdd1617303",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f664737-e247-5c4d-98b4-5a96b118bc98",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a73626-952d-5778-b49c-17cabb9b941e",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f1aea18-a8d4-5a90-8365-79dfdacd6bd5",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f187410b-ede1-50b3-a196-a1911046fba4",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-bundle-parent 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c89d852-6cc9-5b81-bfb4-66be06dec58d",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15b45bab-5f68-5b65-951c-e5afbf2551d6",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04afbf82-6e9f-5009-b97a-ed5ed702e16f",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3830ecd6-7e74-57f2-adc7-f9a58cc76363",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-bundle-parent 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36afc8ef-49e0-5474-8492-24303b79be09",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d376b061-9120-5963-809d-6faceff1e735",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a6e7fe7-41d7-518e-b749-18542f00aeea",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e349b30b-7e64-57db-9385-9e67fe087e34",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-bundle-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-bundle-parent@3.5.9.tuxcare.1"
    }
  ]
}