{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6e86cd1c-ea7d-521b-b66f-31793fc39b26",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-databinding-jaxb",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9fd37655-9fcf-538b-ad7d-bdf5bb25b89a",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7709d3cf-fa85-5f85-b737-69139deb07d4",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe8e6d11-63e7-5336-987b-f1535bb13c36",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8c38a3b-5b41-58c9-a8e8-325096ed7096",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0436fab1-9e72-5589-af57-a50c99765656",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d5e3b8-e5bd-57c9-a8ed-f2ae66eff441",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:982bd528-56e2-515d-b5b8-68ddb71cd765",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faac4ca0-646e-510f-b8ae-8f921dcadb76",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3328954-f86e-50a6-bba6-33b088952359",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aeb34f81-2702-5664-8af1-15e928627f28",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15a0513b-a925-56c5-8423-8b76e666d0e3",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a850532-3ab0-5310-ac9c-2c872eb2e2a4",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e89b246d-247f-51c6-ae37-f51a03e39d7c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:375d8435-23a6-514f-b740-26cdbc318a93",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95da5ae2-87d4-5dd7-a730-71e234a4b5b0",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:437b755f-26e0-5dbc-8d87-344e9c4678b1",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f30f208-f8e9-5304-8cad-af29892658b2",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-databinding-jaxb 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d33e987-87f9-55f3-ae83-69bce0370929",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21299a52-43ed-5e92-bf35-1380194b8a59",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:626456b3-26cf-52a9-9f6b-98e5a98432f4",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b3f9db-f321-5bae-86b7-95a30054b042",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:034aaf6b-38bd-5abf-8f50-ac947d8a6ded",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5218ab06-aa04-5905-a123-1feac7838c90",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc5de041-8f8c-58ad-a65a-0014d949205e",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0427fe2-b4e4-5f55-ae1a-d1b57258bae9",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6070f052-a66a-5aa5-95be-058d40156726",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-databinding-jaxb 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3450883-c435-575f-ba02-94778264c777",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6d527fc-9bbb-53b8-b2a5-2adb32b4e628",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4de40408-3250-519c-a134-b8338229ff43",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41a0b14b-376f-5318-9c14-de37b4816fba",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-databinding-jaxb 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4eb99f5-42fa-55cf-a62b-49d947a53466",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f475c150-e65a-58f5-9f3a-fb18bc47b846",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a85f09f0-b7ef-5c2d-a735-401d3ca20451",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a85d46-b050-5f72-b832-3f8d3c575311",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding-jaxb."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding-jaxb@3.5.9.tuxcare.1"
    }
  ]
}