{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:aabf056f-f012-59fc-a586-2d0a90a326be",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-distribution-manifest",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cca6568b-00d5-5385-90b0-4184b8d6126f",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59946535-ed35-597a-991c-9c6ed4aa43d0",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a81a99cc-69a3-5530-9034-40068d3e4ca9",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eefcdbff-2583-5a65-a105-1250760c8e13",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7144c2d9-576f-5900-8078-7dddade0217c",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:657b1b8c-6983-5aee-a0a6-6c9172cc4b79",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cea7d6ba-4afd-5cc1-b40f-cbb0e508138c",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90c96f14-e1ec-5430-aa04-d7bc11ae9006",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fad73ba-a8db-5160-a3d5-75817be4c8af",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28eb2426-bbd1-5dcf-9685-4031fee5be5c",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01af987f-6a19-5ae4-b61d-d0bc0bedd9bc",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f0547f0-b371-5450-a609-e55855b9d1ec",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3f70db0-7bee-5134-85c8-505e03a75d79",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a775c1b3-90f8-5b5a-ae00-d0016a9ce4ef",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3264db0e-6c48-5997-bafe-4b6c26950c79",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7563a4d4-2d87-530d-ae0a-4bfe836fd1bf",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d146fc65-f3cf-5c4b-9b4a-be96968a1913",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-distribution-manifest 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c23467-893a-586b-96b8-c216d9000ff7",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7d6451b-956b-51ce-ace2-3df11a563d76",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c597b9e3-b2c5-50dc-acc4-8d233c55d43b",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcfb1616-01f0-5ed6-a4c4-9967afd82c47",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2be8a0f-6b87-5cee-b31d-3fe363a7174e",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23180d1a-7abb-51f4-ac59-7d607656b8ce",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf34393c-6d6f-5800-9962-fb898d7c5a1e",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe18ad90-9735-5d34-aabe-a0dd4096592c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6003761a-5e4c-5439-be19-4a8c3f6ef15c",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-distribution-manifest 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e46a893-3105-541f-988c-878ffd822f9e",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655e5cb8-e642-5730-823e-e7695cd9b3c2",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:880dd153-c71f-5b70-b4e7-3c9dad2a8e5a",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f689b41a-8a88-542e-b203-a538a4cfc695",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-distribution-manifest 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9a4a82a-48ed-5f92-a0be-510608c924f7",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f67056a6-9907-5cf0-9e78-333d23f3b1a8",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce01ef6e-87a5-5587-ae93-92de37ad9e3f",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e7e6ecc-62fd-5366-94ca-01368ce7e6b4",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9-tuxcare.2"
    }
  ]
}