{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d556a033-2a23-5e65-8fa5-ad046d22fa12",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-databinding-aegis",
      "version": "3.5.11-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:02fcf35a-3035-506f-a23a-27f25b0cb390",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:094a79c3-7b67-5f42-adcd-00ed352f9b20",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dba144e5-bf87-5c40-b7ef-eb481615673d",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:717d3f04-9d5c-5304-879c-4409179b950e",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f127f966-9f7a-56e2-a6df-317af83eb0d5",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5acedd7-f3c2-5dc4-a145-bc8490b35be4",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b319c751-6f4d-5724-bbae-8ee189b0b987",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3a369c7-5b66-5947-96fc-d4b4cad6c09d",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5322c852-e4b7-5e92-8392-572db3329d97",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cdd6449-33e8-57ed-9aed-016aea1fd031",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f05c5af9-c215-5c55-8239-602184a8dc2b",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:377cd4d6-f7e4-5473-8f1c-2de55ec1b852",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:501ae8f5-99ab-57b3-86b4-cabfcc61e622",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb55bfb-864e-57c9-bb1d-31c316f94125",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5970210d-44cd-586f-81bf-536a15401ed9",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13549000-67b7-5a5e-9531-721a082dfde0",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebf77d38-72d4-50bd-82f6-a4100c3f4282",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56372f59-7078-5180-8203-a3bcce34bc8c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d97a98-c43e-520a-a6b5-48b32c0b56c5",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4150dba-6fb7-5790-979c-2f589569e55c",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8c36ac2-79a0-5185-bcbc-f4093b608bc5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3d409f1-7f3c-5720-925a-e6ee8588bc3b",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d540f11b-2ba7-5184-a5d5-514d3613fbdf",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7c50a8b-6175-5237-8b3a-68d93edbfb47",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0a99cbe-c0c7-5cde-852f-952bc9d1a00a",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3461a5b-e02b-59d3-83aa-c25d3995cab0",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-databinding-aegis 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e361199-7541-5e49-9485-23af764c1628",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:616b9fdb-44c4-5cc5-b81d-61f4a3c5d385",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-databinding-aegis 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a281786-030e-550e-8f4f-6a3241230b88",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e82430dc-aaf6-520f-82b0-49f9ba97959d",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-databinding-aegis 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7172090d-c91e-58fa-bdc0-23642cc5b30f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0aadb4f-75ba-5d9a-83e2-e280558b878d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-databinding-aegis."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-aegis@3.5.11-tuxcare.2"
    }
  ]
}