{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:74a77c06-2e10-5a7e-b54b-16c6be7c3da9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-core",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d8e1b0f8-61e5-580e-941a-cee50e757481",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5036f344-772e-5975-b5cc-e607da21d350",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88373188-459c-50e4-996d-089c81e81b72",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9072ce9-b4b2-5f10-813f-86f46d5381e7",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4597aa26-f1e5-5d25-9e3d-9f310e4435ad",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6871b90-722d-5765-9ab7-42e3054adc56",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f69ab1ca-48cc-51b9-95bf-c53fad731e31",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51ef55e-87ef-5b31-8e73-7306c83fbddc",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16dc998f-1afc-58c8-9b21-50a7a1380797",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77fcdec9-ef6b-5969-b076-7aca089ed823",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f206c27c-27a4-51f7-9c22-b28f941f80f1",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6619c4b4-b8dc-5626-a2b5-35a1f4c45ce4",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7095cf8e-9556-5509-a59f-14b574fb4883",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3610a3f3-9a5d-58be-89ba-8283f97fbd21",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c85b092b-234b-5ed4-99ed-bf282e58944e",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcf35828-260d-53da-aaaa-48250c91475a",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fadaf6d-037c-5941-a533-047df39d491b",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a136a8ed-db28-5285-8544-7eb828f43687",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33aa2db4-355d-5392-9e0c-5bfe96160d9e",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7accd00-2155-5151-91f6-b340d2da882b",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cc0980e-872d-58a3-ac26-f1fb9e940b20",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:616952f2-5df4-58f5-a423-8f91eebe8f08",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d1fff8b-b3e9-5f3a-b0c0-32537fc5923c",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e414c0d9-2e60-5902-a664-e05f872a63c8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e64fa2a9-3ee6-59e0-b643-72db8a3f55d9",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71b9f2c4-1d02-5ee9-84d0-a178f8541199",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-core 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5116f96-73f1-50e4-9d60-65338baf304f",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50086d78-8864-5e8c-ba15-0f8df55935ff",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-core 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b04867-4d5a-5a3b-80f3-e6d5d0bb93b7",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:717f07cb-997e-5d62-90a0-ba30bb5f83be",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-core 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46787281-afd9-578c-a915-4778761392cc",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:356fa441-76ef-5966-a9bc-6f568d4883b1",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.3"
    }
  ]
}