{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8da3af3c-6f8a-5c2e-9d36-6d7aa2914f83",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-distribution-manifest",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ebddd12c-8ed5-5127-afa4-e01328d79b68",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f5074c5-5b26-5d2c-a0a2-12156df34590",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44e03bb9-94ac-55fc-a9ad-6c1708e57a3f",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e544764-b9c5-54ab-b1c6-be1597a19743",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d33f724-454e-5213-86ac-e4740ee55a0c",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:700f196a-cdf5-5d98-a0d8-9f8b69330f55",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e46e58e3-e8f1-5c13-962d-03264c184b61",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53528906-d0c2-50c0-b462-b5dcd35ac1b6",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c5295fb-6958-5674-8c14-6665fb413307",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57425317-032a-55dd-9211-61e3fa942cd7",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a359f7cb-79e4-51b5-84fb-e65008f007b9",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06a57636-1646-54f0-9268-d6951c55eda0",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ab77aca-c0ee-539f-85b4-d60e69ddd064",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25d580e4-e556-5a93-b468-f668f2052398",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6f5aca6-ee7b-566c-b35f-ea029818b56e",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efab26aa-19af-5012-86a1-e7f5b0800c47",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd2f7292-69a3-5e06-ac77-9d9e5cdaa3e5",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-distribution-manifest 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:243a542a-7d9b-56bb-8e60-581aa934d549",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:210dbb40-48aa-5c74-a44e-7ff41f9575c2",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a32fbf-6736-5dfd-9807-f4382a661ba5",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c311158d-3c7c-58dc-9202-20965f880efd",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:809362b1-86a2-5958-9745-8681d0a77d0d",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf296195-3850-5e77-aedd-caf5c3eea5d4",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:651c4bfe-aa1e-5793-86e9-861b401d3d42",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68b0d475-337c-5d46-960e-7b01f71aa6fe",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8751a37-d1e8-56ed-8017-313919524026",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-distribution-manifest 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:832d8c4b-de8d-5818-8792-53a6c4252944",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:620a2c22-38ad-5400-8376-e9fda46e35d1",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e212f7b-81ec-5410-8647-57b732d9d4bd",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed646b8b-8776-5c53-9976-ec47b0724ab9",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-distribution-manifest 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03038569-26c7-57f2-85d0-1a14697ce909",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da147790-c884-57a0-8c57-c72641577a4b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c43f2e49-2750-556d-bb28-8cadc020b125",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23149238-8398-52d9-b047-3765a784bb06",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-distribution-manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-distribution-manifest@3.5.9.tuxcare.1"
    }
  ]
}