{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bef5c09b-b3d9-5072-9a95-56c07fe42e44",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-java2ws-plugin",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f04dce59-f66b-5d5f-bbb2-b1a0833eacaa",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d8aa404-2901-59cd-8882-25049443546a",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3161753b-6f06-5481-b00b-5e94db7febaa",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72124582-f0da-566f-a0d4-6fb5670e2b07",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aa54da8-c467-5fd1-81b5-a3dc06911789",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d3ecec-13e4-5a08-8b30-ab0aee701167",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b096e40-0f43-5d0f-b35a-b30f09c0e70f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:794c341c-3afc-5809-b98d-c31f501a7296",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3df6a3ab-3aaa-5a5c-81bc-c9c591739b13",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66524b12-d852-5c30-b97c-18cca446e1b9",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53c5df76-a986-5a96-ba5c-b24b37bb14a2",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:826a956a-006b-558b-999d-e4255c8c2104",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e544cef-2775-50d3-9c63-07577e014165",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8c99316-0ac9-52e0-a11c-808423d789a8",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90cf1185-9e59-520b-9556-67c286d90538",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aed6024-7c22-572b-a486-ca08fdd4ac84",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8965dcb-81f5-5dae-8f82-27fdc26fe280",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de754972-5062-5999-9c81-8b01909c08f2",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e6acda-c2ce-5c1a-a78a-a4b21310640a",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b10b9e38-846b-54d6-a563-ce2174496507",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e883929-f6ca-5233-91d1-a74d13c624c8",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd03d04a-13fa-5150-ad4f-80e0b90d0a8c",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c77a0851-9893-53bb-84c0-8b97df241dd5",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:902ef6b6-3a4a-58a2-8f81-56bd17180a26",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b550d8a4-8144-51ea-8214-d99b76720a8c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:284f73e8-4af7-5371-be80-1de7cfc3d461",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d45a732-fb44-5070-9b26-bacd1f9ac7ae",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7681f91-d69f-5f6f-9fa3-00f01a02680b",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7303ac43-0df4-5e78-a4da-28c3b2c37f3b",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05cd254d-8def-59f3-b0b0-79febb5ddd7e",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70beac2a-b0bb-5993-9237-49aee15b6629",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d85a3a70-21fa-5757-b6f9-2b7e4b841933",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8a7b638-dcbe-58c9-b477-25a2be101398",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8b4afc-cde5-5220-ba83-361ce87faa91",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.2"
    }
  ]
}