{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8ced8184-5745-5398-9052-12c8ea866f20",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-osgi",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:41d0a8dd-c41f-5d20-9506-028978904ee0",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b64d2ef2-560e-50d1-b592-cc9e14522fb4",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4313e5a-bd7d-5e32-b4cb-ce2ddcaad6a5",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9727a31f-ab89-5790-ac21-39d3bb8c3fae",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a41ce43a-6af3-52ee-bf7c-3a8cf3c6e89a",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c5134e7-2ea1-5c28-836b-5ba38c25ba5a",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:881a51a4-c318-5a77-bcb1-d205a5bb3a81",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bafda1aa-0545-564a-98a3-3d3ec210b320",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d238a9-d948-50a7-ad8c-79e333b3d7a5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80f39883-2671-5286-bb71-e73e7d11bb65",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:680364d2-19ef-5764-98e4-3411890ba2a4",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67774f6-c974-569b-822f-45a189ca9705",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bfce6d9-7927-5219-bcb2-0d6903ba9891",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2121b65c-3459-523b-b9c3-5a7ed58e1e44",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11276311-68aa-53fb-8640-5314ed76d864",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97268c3b-67a5-564a-9c5b-0291e3c2ed8c",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41998d41-427e-59f0-be74-2a5eb8a071de",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8dff3cf-4352-52d3-8590-a79760bba40a",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24e4f143-0334-5af3-841b-8eb7c58b658d",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a079cf71-377c-5400-aeb0-f741a2778087",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d5f7c91-3319-5070-b477-9896f50e1439",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecefc373-0f50-5491-abd5-8316108c867c",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3cf914-faff-5aa5-8bd9-441c6fef9d22",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aff0cc87-bb25-582e-a4b8-b7c914200e10",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51464cd4-78f5-51a6-8240-9b7eb186d3aa",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4442fcc-936c-5caf-b166-a02b814f2f03",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-osgi 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1565517-68e1-57b4-8479-ae9f82e04b89",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e84c71-ddce-516d-bcb8-bca8ec318ca2",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-osgi 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ab24c64-570e-5f7a-bd89-1eb20dcd6c82",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9a3e0ba-5952-5f2c-aa68-e4db7c97bc59",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-osgi 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2646d96-3f60-58fd-b426-18fc826b6dbf",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d886ffc1-4967-548f-a633-852fa53e1673",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.4"
    }
  ]
}