{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:50041121-c069-501a-9c65-dfd47b63da14",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-java2ws-plugin",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b9c41f81-3a75-55d4-a414-17229332bb54",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2440fb6c-e47e-5af1-81cb-78201fe24aa3",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ece8d86-c64f-5717-9678-2f47a29e7cd0",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70b100db-507b-5b54-bfd8-19ba4b1b4b97",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8fdf368-ab22-53e6-abcf-17ff74b9d522",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de66f3c8-05bc-540f-93fc-acc1c9be3d47",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99da8761-4e9c-5aab-8acd-f37f08f8334b",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01c56b4b-8524-5192-af69-912b674d5bd4",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8062d006-4ea0-5196-b82c-ef8287785c0a",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70ca92fc-1e22-582e-bf49-1d787d05965b",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee1d1b99-67ff-5f2f-bf32-5d6a771ddf9f",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d28664-e67c-5882-969b-a90dbb7ed912",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20f3cf81-86a4-5abe-ac88-de1ae7904396",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e3f8218-f8ff-59ab-8152-c02e39f46018",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe4e60ae-befd-5a66-82e9-d131e8df06a6",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ee45d5-8958-579f-9f27-483b3bbff6d1",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55671436-0690-5e15-a5ad-a1089936ff96",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad0ec543-30d5-5267-8bb4-2109010be33d",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb6dae30-0dc9-5e49-a5b1-9d53eb6ead05",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2464a9cf-83ff-5b02-9425-d14e3d86bb8b",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cfc1acc-8f21-5aa5-9476-8fdf39d63654",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c0942e3-28f9-5c4b-b97e-64c8cc944b2c",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1468c5f1-be3a-5c64-bdc5-95538fe0c601",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8898f7e3-8fe5-50d8-b033-16a74b225b9a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0c10e52-c890-5cdc-b07c-56c89377a8fb",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4e68c4c-fdfb-5e73-b69e-479b78e93a3f",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58293f60-f825-583c-9680-10b58d3ecd04",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9edad36-383d-5229-ae20-2103fce457e2",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97fa008d-c32f-5061-91a7-b0eb7a02ace3",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e317970-f140-51c6-8cbe-8f453ac2082c",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:085c1a32-831e-58b1-84e3-a87ac7ae4553",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63fb7733-3d6f-50fc-9dcf-9d69d5beb6ec",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.11-tuxcare.3"
    }
  ]
}