{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fb716468-b781-5730-b241-e27930b96108",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-tracing-opentracing",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:32478037-4663-5124-87dc-f71702cd8114",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89218f47-745e-5c09-87b3-944335240d5e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:772cccc9-e8a2-5400-9b22-808d81db3901",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7f2dd2e-7ce9-5d61-9374-c2f897d5494d",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9217b961-8995-57eb-8b36-c1401990df77",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0bc4c49f-85b1-5417-b559-534c33f97f1c",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e8c09a1-f13d-502b-9eb6-c4c7a38b6e91",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d27d591-72cf-51d6-89f1-afb913019529",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eff658a4-b121-545d-8a71-37f261820059",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6869e5a1-8ace-5c4f-9b67-86a2aac7a463",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e51260e-2645-5b98-aaf6-47914658c326",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5fde6e1-12d4-5064-9a95-3bac47798f75",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9033d019-5613-5905-ac5b-79518375f00a",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6ebde9f-46f6-503c-af90-7023052f27d7",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83842731-abe3-57b6-a5b8-6262f3cdaa99",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b7ab60a-ee42-5350-95c3-700d0d241446",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:260b2954-238a-531d-8f01-cf756d5bdbcd",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-integration-tracing-opentracing 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc6d8d8e-bfb4-54df-ac04-55c6b30e0460",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:297bfb12-02d9-5902-b61f-b20a85b95a36",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a017ad-61ff-5400-a609-d39236226733",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27b66045-25bb-506c-8f3b-a0edaeb9b1ca",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:511f1460-651f-5174-bbd5-55f1f62bc621",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:035afe43-34af-585c-9ade-a2f3824828db",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3fc262a-df32-511f-983e-87bd254a46f5",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fc9b99e-192d-50e6-82bd-a021f2368795",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcb2e519-ab5b-556a-a9bb-c78b944456d2",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-tracing-opentracing 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ccd1085-06ce-5e87-8c82-de96f3aff3b8",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9f811c4-6adb-5dd7-8b29-eb5889ed6a6d",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d2181c7-cdc2-5b51-8b45-92f4ee8e1ed3",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8433381-ff33-56f4-b738-39dbc2cfbc07",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-tracing-opentracing 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0efac4ed-aba2-5d84-a152-d7e0a3915c79",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19736ab4-1769-5516-9015-4784a1e5430e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa08fdca-b7ad-58b0-923c-41c9afed43b8",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:887e4e95-c8c1-58e9-893f-831c3073d092",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-integration-tracing-opentracing."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-opentracing@3.5.9.tuxcare.1"
    }
  ]
}