{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4b06d976-fb45-5198-a07b-da769a351bb4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-tracing-opentelemetry",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:afd087c0-e70d-5974-85a1-8188219898d1",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6efa5081-ed00-57b8-9dde-2c0e4033d46c",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:435c2cf7-4fae-5f95-9245-2aac97c4b539",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54e9ff70-b497-5db1-97f1-b8cb82847617",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6678ec2e-77ed-5de2-875a-86664fc4f764",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c62aa970-646f-5cca-a19e-cad23d1b9ec4",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcadd96b-329f-519a-8586-ee36d8eb5b6c",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ad9ffd0-ccae-52f6-82b3-0cc4247227a0",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7923a43b-2af1-50ee-b8f2-12789e2ac1df",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa8d0ec-8a10-5b23-8094-8cc9c9b8683a",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abdc0c3b-2297-5af4-bb53-28293d67e2e5",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:999542dd-ba6e-5df1-bb96-1db07390d489",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a468adb-b6c5-5c53-8994-36c703f2d153",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e745902e-2c9b-54f4-aec9-466e2dccdc6e",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68d0b6ea-1b17-5205-a79a-d5dc24f50d11",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:091211ed-367a-55dd-b150-304317e9d071",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c87289c8-d034-5e93-bff6-394ef0f1429b",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72c867e3-2904-5b2a-a7fe-1cd14c42488b",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e99e329d-4e01-589b-9680-18744d31b3a4",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:686fdebc-b8e1-5b6e-82a3-5d587ec60dc5",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c00e7240-d0ca-59fa-94ca-171e2e77cc8f",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffeeacf3-0c32-56af-9362-863382726b7e",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d9cc77-1b77-54a9-a8e3-1b68a59aaea8",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6e70ac-03b6-5de6-9d17-4ac5d2b2c4ad",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0baac323-cf16-5d27-a15c-e19b753c48da",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ba1cad9-fbb2-599d-8894-7c1f3597eccd",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-tracing-opentelemetry 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62a23fe8-c6b0-50f6-a30e-5d7fb964fad5",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab3f7a1-9f37-51e2-93da-dcfd958ca690",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-integration-tracing-opentelemetry 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e1042c3-e484-5711-a629-6131a54a146f",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5bcff73-8717-5afb-b0e0-6a76ef2e145e",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-tracing-opentelemetry 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c9a55e-eea5-5e38-843c-62bd43f6f5ca",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0d2a562-68db-5dac-abbd-3017ee082ea5",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.1"
    }
  ]
}