{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:defaaf81-01a8-5c41-b756-c783b666abf8",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-jca",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:bd505c0f-d15d-5a49-a6d2-f77ad3b5e078",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cd72bcb-3698-5ea1-a133-87985a8ff6ca",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d808a61-3b54-5239-9ac0-3d314dceeeb6",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:977bb0be-9c95-53db-8e88-f8c9d58e76dd",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:540b00f1-0b68-575d-af83-5771fc73a603",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb127c9-66eb-575b-9eea-342ddcea5d4f",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b405e66-e2fc-54f4-8a35-6e24e24948f5",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a919217-24f2-5942-b673-ae9700d7b708",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f2bc8bd-74e4-5294-862a-cefd8f21e782",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f54635a-72d0-506b-b27e-c07e1ac0b048",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5710b0a7-92e4-5f97-a44a-71e786163797",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be03a147-3de8-5ebd-acbb-e93e651e72ec",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1cda898-b9f0-5b45-bbdb-57e9793c4497",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e7e5147-ea65-518b-9eac-b094160cfc26",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91191ff-1297-5a82-8135-264d0a33fcac",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87602411-2b31-5f58-88de-7798195f5176",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:584a0c4a-37bc-5bb3-b79b-c06a617cc29f",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f66b994-0262-5135-bd4a-4a100bd0f881",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55314901-d5ec-5c62-b80e-91d1606d21e0",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81786ed6-08de-5faa-b055-3447f71747ad",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f8bcfb8-681b-5518-8d51-f534c559edf5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d65984a-8b79-53d6-9733-26357a881475",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9ce4b42-89b7-5f2b-a8e4-fd6938da21fd",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a784193-dfe9-5cc9-bd99-f6845c8646e7",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f93b32a3-727b-5bdc-a563-92a003097ab8",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63536aa9-b8be-5e94-a4d3-d9a3d9259bde",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-jca 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb1f951-fd55-5c0e-9c47-5c6698db4850",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:295b6f90-9288-5aa3-bc76-c15e4dd3b5c0",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-integration-jca 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffc56673-a08d-5a8e-9ac7-996ccb6f611e",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59b08f18-6bfd-52f4-8af3-30399ee8c6d0",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-jca 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c83cd56e-6335-55e7-b758-197f15f39394",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:222e748d-dd4c-50cd-b03a-a8ff7ebd4ada",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.11-tuxcare.4"
    }
  ]
}