{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4baf06db-ba6b-5891-9431-ee44eb003e55",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-bindings-coloc",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:76496afc-b877-51ad-8bb8-178cc235952c",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:988553db-5acf-5e70-97da-caa19cfea890",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5019382b-d68e-559f-9c2d-de0328dc56cf",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afd4e35d-a9fc-5e22-9f55-1c74484927dc",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06fd72a5-5ef2-54e5-8df5-2a0ed087e8ff",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db17c982-5573-5754-b4ef-b1c9aee9f445",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70d7a7d9-489c-595e-bf0b-f52b8ceeec3b",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc69e88-389f-5476-a821-d35f2d5537c4",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e59036a8-e8bc-5df2-984b-1c21b298d527",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34a268cd-019d-5068-9e94-963c2b700b91",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89070b8e-eb03-5b7e-9f09-22f5c0f7b88a",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c22c5e84-1bfe-5022-a376-12437349ff13",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9032ca47-7d27-56ac-a7f7-5ce817ecbe83",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f0e94d-f4d3-50b8-8294-a01cf4d714ac",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36c25c37-0965-512b-a544-2ce097c04d6a",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8224c77-eae2-5f71-ac2b-ef3f3864e132",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58becac4-81ab-5760-a38e-d9f347fcecca",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-bindings-coloc 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c37c61a8-4f70-5370-9f0a-281bb47bd5ef",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c72263b0-d2f0-54cb-b7b6-0a2c3f9ef548",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa8e499-f16e-515b-97ad-e4721999c95e",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8506f712-1e75-5a05-8395-df5e8a727ae7",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0b6728f-6272-56ce-bdac-2144bf12c2b9",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97dcc3a4-387b-5af3-ba8e-4530366b3461",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b29e5df-68c3-5e49-859e-df397fbacb83",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f93fb0c3-c050-5e19-8237-fab48a5dd289",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ea564c-c00b-5071-86b0-4e523e7fffc5",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-bindings-coloc 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aebaf83e-4b25-5951-948d-aa13c133c7bc",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7f87adb-b3f3-5208-ad6b-df6777978385",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67a0544-ebe2-57e3-846e-2e09a1367b16",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ab3708e-6a84-5b83-b6cd-89b47360f971",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-bindings-coloc 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e2f3a4-a7ac-5ab8-9944-68f307b56a12",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db60772-9d2c-56e0-b197-a7ec6c5623c0",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b17bdac8-784a-5534-89d0-ebcd762d2a4a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5e8db5b-ecc3-5349-84cf-fabc3314da45",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-coloc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-coloc@3.5.9-tuxcare.2"
    }
  ]
}