{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a038e276-8d9b-50b7-8a7e-68de680f4f9c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-parent",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:02ba117b-4342-52c5-a8ce-0ecaa02e8fe0",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c503657-a8db-5d7e-a810-441fec6d7b9e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:174f3d36-9895-5ba8-8153-f8fe44dc7a82",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfcc1d01-500d-5dc0-9f4e-132b59b88c73",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa8e5908-f732-5636-859c-81f46175e3c9",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf8a7a35-1225-5686-b8b1-74e7d636eec9",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:595b26a6-fd7d-5093-92d7-0e98f5846517",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:973ba285-8044-5315-989f-840b8d5edbbe",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a5e5586-8acb-57a9-9430-51a9fc19cffa",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e075f05-db40-5cd7-860b-aaec315a678f",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a734c65-2f0e-5eaf-ac5f-ac0720c8cd42",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91fa9bc0-cae9-5662-81cc-636a87a204a3",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1cb67a0-3c6c-518b-a1a0-2146c42f439a",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:853c8670-8e3b-59b9-8aba-4cc54fbc6159",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc80beb5-7361-55d9-a03d-76712de201c6",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1126f1d3-fa5e-5fbc-be77-fe6ec937474a",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3fc81d9-721c-5d12-8562-af4749041ab6",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-parent 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c44d9c20-17a6-5b88-b2f4-15ba494cdc5c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e55ebbd-e2e2-5257-8c16-713c62c4bba5",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cfbc8eb-f8a6-50d5-9302-971ae2e84d02",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2f87a1-9f0d-50ff-b555-4e87e7fbc4a6",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69a0d9d4-e07c-524b-8d6c-78e9cb8be8b1",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf65bb95-c5b4-5caf-b377-786dab8a1393",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd5ed441-4b4e-5c67-8def-fd99d8446694",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb4607c-18e5-55c8-aea7-97e6139e4549",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:424fd013-7132-5396-a6b1-bc6cba913d33",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-parent 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c58abd7c-1d3a-591b-8e1c-e2cff1588787",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9812af8c-6bd7-53fc-b1ef-22f45988ab43",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64d43fcf-d455-5898-aa7b-07b1833aff03",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b1615d2-ad1f-50ee-8f7d-10e82cf4e52e",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-parent 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b27c88c-e347-556c-ac7e-c7c8eec234fe",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78fd6b7e-6833-5d1f-afd7-5e92eedfc37c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dab05685-0917-5ab6-b9f5-6546e638d9e1",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea5e89b6-1f24-5239-9de1-66a90c4debba",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-parent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-parent@3.5.9-tuxcare.2"
    }
  ]
}