{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c152832b-1b76-5a83-9414-d4d299ff9cfa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-databinding-jaxb",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a30c9b24-84ad-545f-94a1-ec79422e0c2d",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f7975d-b5f7-5f7a-9290-0f6ec2e14a52",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb4d3eb1-96ab-5aae-9d19-06ebe9a3d3ca",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241b8270-51e7-519c-bf73-dcbab7ee4812",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b484c9d8-7006-5e4b-a6a2-6c4b6de7f188",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21f116c8-db55-5377-80b3-8abeabe210b4",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eabe8f64-9636-57e0-be51-c9ee608ceb98",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d35ffb-d2c9-57a0-9cfe-891738eb0502",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b2b3c75-07d5-5571-9cc3-0d83a85305fb",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:703980c7-f5f0-5bb5-ad92-9bf07b99cd14",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:928ddb2a-5e29-549b-9baa-6c523ad80397",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a42556-ec76-59ab-bd6a-d48d0c855a3a",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64e7aaee-dc20-5101-9196-915b86cde367",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0026f46f-6ce4-5e89-8cf8-0659a51262e2",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59e5ca97-4ef6-5b7d-9e1a-c7709b761ecc",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f054a327-9950-5ad0-800d-8f2e77f07b90",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad9028d6-3eaf-5743-b2ee-4760bc2759ad",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:682ec0fd-fd96-52da-b444-a502927caed8",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ce8d3a8-e171-5abb-9ed5-7de67f972980",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d8b8ec4-1f8d-55cc-a192-d78b447da999",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b917603-9acb-5622-b1d8-c3145629edb5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f16e897-b838-5e5c-b270-d7ac19540a21",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2705dd30-4e1d-54bb-a162-9f8b2805a77a",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8181394f-4e97-5ecd-a7b6-8f993a70d25d",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83eb151a-5a02-5bd5-b80c-bcace556a2be",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e896a39-bf4f-54d8-8b75-c0ff9415398e",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-databinding-jaxb 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6f46a5d-0364-5a2a-bd4b-2446ce4afbba",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecc0c243-1c35-52c7-89a2-fe62b4165dc0",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-databinding-jaxb 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d410b2-affe-526d-a44b-a18fd39ff423",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1592b5b-3a72-5a31-8151-3bbcdd45fd54",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-databinding-jaxb 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1aba74c-e5fc-5e18-9e2b-a650c1d856e9",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bcaad1d-301b-5a71-aa1c-50692f35a472",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.11-tuxcare.3"
    }
  ]
}