{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:444b5073-5f5a-57d3-9794-0aca49456459",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-jca",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ab47fb95-ea22-50c6-8ea3-02359a45fa2b",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:705d28c6-ca2e-5504-99e0-7e02987230c4",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a94a856c-6e42-5abf-8d1b-49038715e012",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e096b2b-0f89-502d-aa9f-54c0ef47e4ff",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6303e64d-5bb0-596d-a871-724852d54b84",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc385ce-9cc1-56b0-b3a3-205dc3f253b5",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eeff6be-ba61-5dda-b18b-ff2dd0645c29",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05ac3fd8-4484-5731-b057-48b49dc35501",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1172c165-7401-5e55-ad82-755c084c663c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cba45e55-c10e-5fee-814f-cdba70a1b01a",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c0e836-1449-5f55-b233-5f055469692e",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a0c0ad1-4c8a-5b68-b867-1bb7a31d23ef",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89cdcdff-10a1-50b1-b4f5-698300fdff26",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24785523-5be7-5800-851b-95c76eb9912c",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18caa65-ce4e-5ce5-bab0-3792aa9a7f5a",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dd5e3f1-6f9e-583d-916e-735624cec406",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a50d0f11-5821-5881-8dfc-3410e7edcb7e",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-integration-jca 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7830c875-45ef-530e-a082-e01344575d98",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c44bf782-f99f-5a64-83b2-69771561f682",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc0b10d8-6545-52ca-98e9-0754179256fb",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:152fcdaa-ffd8-5ad4-b71b-3da7818264a6",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d058ea-42fa-5d46-bfb2-ef2cb4644b14",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a102eb7-4380-5e31-9f4d-8881426bb0ea",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ab3a148-0156-5daa-a013-75d5067c036a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7788e108-560f-5c8e-aeaf-054196a0cc0d",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7872cd5-3443-59e7-b023-a983b6faaac2",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-jca 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17883a35-c9d4-5480-ae34-32a7ab494305",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d97e023-40e6-54b1-bda7-7111b6ae6ede",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:920ff1e5-c42b-50c1-814f-f272337cfc23",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db0a83c5-b844-5254-84de-c5a5a4207475",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-jca 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f4d71cc-7eb1-5697-b1db-98fea7b71b68",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd209df-76eb-5182-82c0-dee71919ee2c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceefa342-4e3f-5cc8-bb19-f63574f99fdc",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb3775bf-6b7a-5f91-890e-3f5c06a1ba6d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-jca."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-jca@3.5.9.tuxcare.1"
    }
  ]
}