{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:97fc6b5e-ca6b-54e6-a97d-d09f00cddf7d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-maven-plugins",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c890e4ea-f7c7-57a9-bce6-262fb7462420",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e7575f2-d2a6-5b57-9a58-50dc10b98a9e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:655777b7-c518-5c9e-9550-744278129056",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fb34766-c42e-59e8-86d7-791f5317976f",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:135f66fc-7a92-5871-abc0-244fa3de7046",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e14f93d8-ce71-5386-96e6-53a240e58b9e",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6541c7d-7aab-58f5-acff-c73af015dd55",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc2192a4-9e59-511b-bda4-afbbf25c3d95",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb9b39c-17bf-5ba6-9746-a010f9a19380",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17eb92d7-5350-5051-9759-253b12e9f154",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:470b6c60-c872-5803-bd95-f623bf26594d",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7e2d92-ce98-5089-94f4-6378c136fdb9",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4235f2df-7e66-5b7e-8628-1e814d6c22ac",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef64c1bc-e901-5a97-ac42-60cf5627f3f2",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7781132-226d-51ff-80a9-a40a33bd14f2",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3bbcd75-eecd-582b-a283-d5161d98afe9",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a6dd20-f49a-5d7e-8c1e-dfa4326d464c",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-maven-plugins 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc396ee-c674-5705-b0a2-2194ddc2cf23",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2faf1fe6-3fd0-563f-85c4-ae1228d70574",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:036f0fe2-fbc1-5b56-bbc5-14186727f542",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f3eb520-8f5d-58a5-ac0c-54efba91e695",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:636877b9-0cc2-5aec-8aa2-bc017cfc0c49",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1aff8e05-5f90-5fdc-8a6f-ab83b55f6a22",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:634ba4e6-aace-5172-914b-5c76dcb3d3d8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7868d828-0bcd-5819-8154-ca03ef3271ad",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3ba0a5-0491-5278-88e4-3464a8e74f5b",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-maven-plugins 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f65f404c-24b4-513d-be4c-a8fb5184a80a",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7018ad51-c1de-5bb3-ba58-551f92ae4ca9",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77040b9a-8d2f-5ba5-b583-2185a94ceebe",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aef545a8-4200-5f64-80d3-0d90eda70469",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-maven-plugins 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bddc91a-ef0e-5cca-9d67-7b9dec9ddbf6",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a5fe41b-9b48-5806-9cfa-f13b33b10eba",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8d4490a-74e3-54b8-84e3-219b91242af6",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4389c7fa-bc1c-54b9-92c6-173ca005e894",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.9.tuxcare.1"
    }
  ]
}