{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cf85202d-9caf-50cd-9513-7082be4cc18e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-repository",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b56dfd8a-70db-596c-8448-aa6ff28bf977",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23bdfef1-3291-5489-897c-939bee56c7a2",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05ce931e-18dd-58c0-be4c-dba281e65d97",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870ddb70-20ac-5456-915c-203a4eb63693",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03c2fb51-aeee-51a1-9b19-dac2790fc8eb",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e62f1f4-8a5e-57f1-9866-90b62a8bc5a9",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8b21413-803d-5394-aae7-081df0647945",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:917b9bd6-712b-5b6d-83f7-2f57fb001f11",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb7c1d0-b8ff-51b5-8c65-145e442c0440",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6e40540-b911-5916-afd6-03d4acc31269",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b247968b-957c-54ac-a08e-e9f782c6bab3",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d657ccc-795e-512c-82e4-a1d90e18f549",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fc082cc-ac86-5f85-8b53-401fc741abbb",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee14806-a6ec-5560-8226-736d74b3d60a",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3da36d1-e2eb-5d09-b599-c30803eaac0b",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e32ff973-7733-5a57-b4ee-b2e566855958",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e529bc81-4243-50a8-8b63-660d412e3a99",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-repository 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a797d1aa-35d2-5e70-96b0-58c2aa669f7a",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4af6d8b-265c-5d3a-869c-203d4f685ad8",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc858747-f035-5a5e-9a17-49170546e1dc",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b8eb053-c1a7-5ae6-a5ba-383b4bc2db3d",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75478b66-e68e-5850-8016-aea689dd5f69",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb15290d-04ce-5dc6-a4bc-3a7d11865aff",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6022c142-0c8d-5235-8422-4a3d678088bb",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391e0615-1b20-5cd9-a753-767e9bfe3759",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b81816e2-f1cf-5b61-a91b-ca2fa3385e3b",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-repository 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79e6d8a6-e66f-5591-a9cc-ecda2db48fb0",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9d513d-ea61-5317-a5b7-07dcc63b7286",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f813552-63c4-5db0-9886-5048a87fe83a",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0a3aaa9-e4a3-5f5d-b7d3-1459ca120ab4",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-repository 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cd7e9e3-35e2-5721-8732-79b5e1c04f34",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19a8376e-60ca-55c2-badf-be32e4a50e90",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b3ba0c1-6106-5a9f-85eb-7f5a66b7bcf2",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49912fa8-12b6-5ea1-8dba-7935c9b72675",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-repository@3.5.9-tuxcare.3"
    }
  ]
}