{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:238b4a1d-8eba-5b02-b08b-7aec8913587b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-java2ws-plugin",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:47629337-9eaf-546f-acaf-4b7a65094180",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bf65781-a963-5bcb-96cd-0a11f45f3299",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49c5b815-bc72-5d53-8020-23f3c72c1cc3",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab4a8db5-f9bb-5b5e-90c5-b297596690e1",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e8b8d5d-be7a-5409-b5d4-54b09d150f10",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a6e919-92f5-50ee-ba28-f801942cb4a1",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49f8757-e0c2-53f1-8740-d4aa48c0fc7f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18fdfc8a-2b53-5005-867e-3c874df8e393",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15151f4f-d077-57a6-910b-fdabac819c27",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e88118-0295-558d-a013-c7ffb91f1694",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:908f966e-a860-5972-88b0-d44ceb0d3cc2",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f1717b1-2b2f-556e-bfb5-3447d26f9471",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42aa65e1-b68d-5ccb-8ad0-5ed58d9d1307",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97460dd7-10ef-5f19-b613-f6143c091335",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:161810a6-3b4f-556b-8bd7-1bfeaade8bce",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0bc3201-c21d-52b0-ad77-8db89d4642a3",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9daa08e1-fd76-5cd2-b670-0d18ac62f813",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59cc1bcd-8d36-548b-a817-681cecc0b1e0",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:456119fd-0922-5680-bf83-66f89de75388",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d53af02-84b7-5784-9abb-4b4994cb313e",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:679ddb54-aedc-53e7-95cf-d59c6f8d4a93",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46c9ef85-8c75-5a98-9861-2070dfe28678",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9ae762-399f-5bee-a03c-810158c070dc",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ae36c8-a4ca-5d27-ab34-efccfe4a183d",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d3a809-7cbd-5cb6-91d8-f63935cfc19e",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1cb4d23-1f07-5110-81fd-869efbcdd023",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39465b47-c84d-53c6-a3a8-3305d39420c0",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dfb6c71-8d28-504d-a298-ac0cee95a66c",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1acde780-0f91-58d8-8f9a-7e9f08a3f5ff",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11dd2367-5dcf-5f53-a692-81e8a6da2118",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-java2ws-plugin 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c34c655-3533-5381-ba83-8a8c299979de",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c29411c-916c-58e5-ae74-4c2ba82a4c89",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9081abc6-f177-5f27-9240-c55b23b7417e",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b060b42c-9515-5e00-b694-f9aeb10729c9",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-java2ws-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-java2ws-plugin@3.5.9-tuxcare.3"
    }
  ]
}