{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:04eda43f-8983-548c-b6c2-ce8df114ab8a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-tracing-opentelemetry",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:33a5e08b-50d4-5b22-a1cb-268a6cf97b75",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b46f114-ce3a-5ce5-b76c-85fc76f47035",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf48a310-dcc9-5ca3-b3fe-a24e6e70aa5f",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:547b0b6d-244a-5361-aa03-652bf9cbb080",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64738d0e-ddd8-55c9-98e8-fa1012bf3f32",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eab53a6-01b4-54f4-9847-e73059a09714",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:057e1f59-bd2c-5259-b701-e42829f51ed7",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3aae34bc-9c13-5e9d-9ec9-e4e87fea522c",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72321b5a-3604-551b-8105-58888a54efd5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:257bb889-7bd6-57db-9e8e-c9b90e7a6da0",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1bbade9-4e3a-526d-bd72-8b777f71537b",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5d942c9-2081-5ccc-ac02-a768b2afa888",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e38f887-3206-5696-9480-c91d34b6b389",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:681be3a2-2e0f-5c16-9b4d-101d9152e4c2",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b8981c7-8a85-500e-a9ea-fc7aaf105d5a",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:121a5ba4-a9b4-5b9f-bbed-85c439d5b7df",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa5afe24-2cbc-5aa8-a60c-5b06d27078ca",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab6d36e-de41-5527-9468-232f4f4696de",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:364f1972-517e-5b26-ac83-da4afac26e4d",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56aad082-bd98-588c-8818-cc46f3fa06d3",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efe97c02-79ea-5d12-83fa-5cf6f31c1942",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa5db1f-9832-57ca-837e-0cff22f1af46",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de5248b0-56c1-5ff7-97e8-08cb0d686408",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7a3e5d5-3c6b-5ecd-b3cb-d95f003d833c",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c6ccd4a-a8d0-520e-9035-d57de8a46802",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:195e92af-de34-585b-b42c-d9d313eb0157",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-tracing-opentelemetry 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58d61c0c-3d7a-5af0-a4c1-761d4d3fcb52",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7b85891-9644-5ca3-b6c2-93ae8919cf2f",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-integration-tracing-opentelemetry 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a169caf6-09df-5423-92df-27b52dc62d2d",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73497e39-60b6-542f-9db6-0f51548a378b",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-tracing-opentelemetry 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cc79713-2767-513c-aa10-2bd4090c04a4",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:515131ee-88a5-5215-8fca-cf275931e9f3",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-integration-tracing-opentelemetry."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentelemetry@3.5.11-tuxcare.4"
    }
  ]
}