{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c443354f-08cd-5695-9074-29b86b9615ef",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-core",
      "version": "3.5.11-tuxcare.6",
      "purl": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:84359176-29c4-5f6f-82f4-9b99b27d0aed",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee11cbc3-a400-52d7-9c0b-b7577b8379c6",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9516b922-394f-5ce3-8f66-6d66c41a1cef",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80888c02-c995-5d9b-92d5-edba6eae4ea7",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce5e0897-1c59-51d7-bf94-dca9aa85cb21",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de3ab47e-b70e-5d5f-bb17-39ec94cacc05",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ae3efc-d598-5806-ba24-17507abce26f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c55cdc6-4d5d-5b4c-88c9-be708808b0e2",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:764db2b8-3a6f-515e-91c2-2a8487441ba5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89fa23d3-ac7c-5dd8-9b7a-a11f3f9aee1a",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eed7fb9-9032-5b5e-87b6-f1693c5eb3bf",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45fbcd95-c800-50cc-b28e-5c16aae4af6c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3a4822f-2c51-5107-9fec-db228d62149e",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c6ad115-5f02-5392-a91f-c09249515207",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:439b91a8-d7a5-5d65-a18e-5c35e3d9bf15",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530d38ed-641f-5d20-8f81-cdc19f800104",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad2ea61-31b0-58ca-85c0-d8af7dffff25",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5239768c-1e51-5454-9f6c-1205bac46de9",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9420ee38-8732-59c9-951e-3b22e0ee2578",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb901ddf-44ff-5d70-9f52-d518bcba844f",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b59e28b-fa97-51aa-a491-4d0444111e00",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02931dbf-d2d9-5c52-9db2-db5015bd9033",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d41ae7e-eefe-5804-9364-595cade81216",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b914cc7-1134-5320-ab46-dc094a1a1334",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c197a86-c7f9-5450-bbd2-56a994d1cb57",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3695232-81a9-56c2-9514-dbc4c9f8ecd2",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-core 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e8b0f8a-bc3e-5490-a220-5ea74d4773fb",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05fb1961-23a9-537e-913b-c2a599881ab5",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-core 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07df10c6-4d79-55d0-801c-acf039115d66",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca256684-064e-577b-9f4e-b97fb38855c6",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-core 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e31b5e2-6bbe-518d-82e7-d0fb6588046e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f423d9e-30e1-5ec9-bd46-8875b47f4c51",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-core@3.5.11-tuxcare.6"
    }
  ]
}