{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c714a3cd-000b-5d32-829f-03795cb8dc32",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-bindings-soap",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ba404bf2-c4df-59e3-9b7b-fff3c299b6c7",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1b49710-4e48-55c5-b92c-24e36d19f246",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:406f81d5-35a9-5881-8a45-1191d07f1a75",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7762d2c3-b5be-52c4-b26c-31fa3d1321d1",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84fcf070-762b-5842-898f-bdfcb3efae30",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee8e7e2b-1d9a-5e67-bc32-40377d364bda",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7c3dd6f-281f-59d4-8ee7-463de1392de9",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:974767bd-18ad-544b-a659-ed07e2655ef8",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09506e3b-12b9-529f-996b-8943b4482590",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed772f3f-bf84-5a24-a756-e9d2e3f676c8",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ffcce72-2d97-5f6b-b86e-d0fa4c7bc839",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a85aed6-80fa-5f40-848c-d9d87041f75f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c47c95-1b30-5dea-b940-da510485c08c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2673e77-4997-5175-b907-bf5ddbcc0ff4",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5de6a0e4-0449-5582-8aa8-79166ae95c33",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7954aa8e-4d21-52d5-8155-a164349dee7a",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9315e90f-8158-5ff7-bff8-21571f6cd44b",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-bindings-soap 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8eed9886-6239-5346-9fb5-8a31b6b4a771",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1d53c58-5a0f-549f-affe-18a127826b4a",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f07bfdae-47ab-57b4-9262-244913da63b8",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:876cb5a1-1cfb-5d1d-8430-e9089d6602fc",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:075da6b2-6688-5673-b693-df851168c348",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ecb34f8-5321-5cf0-ab96-33f8916e4dcc",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42fbc0f2-ff84-589f-ae42-bf41fedf91b2",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f75f84cf-a57b-54a4-ae86-aafc74f654f5",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8b100cc-2f09-5d3c-9bcc-a5076b74b2da",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-bindings-soap 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:705174f2-0355-598d-a4a6-977d68570763",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d63bb8b-a177-5eb0-880e-0f3570248bf5",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fecaba71-4254-5638-b808-65e7b8b6b947",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d90a8a5-22c1-5816-bc0e-a8420ca2ac94",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-bindings-soap 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aabc40f8-f180-5b10-a2d3-3789a6e19176",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17099948-58a5-5019-bd57-86fff7b09011",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:464d2190-888d-5f2b-9d8c-8fa28e69086a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:170ffd5a-8653-5c3e-8d50-91c184d7ca21",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-bindings-soap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-bindings-soap@3.5.9-tuxcare.2"
    }
  ]
}