{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:32f73219-37de-57c4-9989-18d4106393fa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-databinding",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:255441be-b5fc-5021-aadb-e1d9ba9544c7",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9da84b9-51cd-59ad-9d62-793bee59ec4d",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:040c4577-123e-5968-8933-3168cb97a8dc",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:981ca618-5cf4-593b-86f8-68270921fe4b",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:200a93a6-4a4d-58c7-b1bb-c33a9e6c5ba5",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bb884dd-a31b-5e12-b330-5678aaa2ec69",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c31a65e2-704d-533c-b73d-7df717387b53",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f7feeab-3334-5b5a-8a97-df7379fd06df",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ea54137-f6f5-5fc6-8248-9e86f624717c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a1a759-4d1e-5585-9d4d-99b2403e9d06",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42642cbc-0aa3-5411-9e98-042fa90fc70c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:304e6791-f997-5064-8fa8-2352cdc9b5e1",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9313c34-dce3-5a6a-91f9-e35a361f3520",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:683704c2-3c06-540b-8d7b-17c64946b852",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cab338e-d1a0-52d2-8902-27ded0617341",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27790ce7-3a58-5d67-a61b-478e124eeaaf",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53f5a95-fde4-56f4-89fd-7ca608d11776",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-databinding 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08d5ddd8-c380-5f11-a793-7c5f50463dd0",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eeb803e7-2eb6-58b5-ab54-e03d79a808a5",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3a4563b-69f8-5e8c-b619-e9c06e0a1f49",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75d049e2-1ab9-5976-8621-531db065fdef",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e06bddfb-b528-5138-bcee-d0b694e141a6",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54f8e0e8-9ff1-51c0-8463-1f517211c520",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fea273b7-92b1-52b0-9756-ba753f909bf8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed95e778-6cdb-5c9b-8a04-fe1dfe879563",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c835eb-16fe-5026-a0cf-a388cdafcc91",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-databinding 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28814255-cf33-5cef-a999-2097b3c1ca4c",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:331f9314-4571-5d33-92b4-a616aced4755",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789f3e7c-9d7e-5b74-b774-47895d7a8b81",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6215e79d-231d-54b9-bf9d-5e7a569bd201",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-databinding 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9eb0647-01d2-5461-8355-0e557fc66ce5",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b1a98d1-05bf-5f0e-91d3-987e6cd76edd",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cc7a34e-6381-5d38-9475-ba84d41e7b1f",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a39f3f8-0f6f-5696-bc72-e2adde3cb2d9",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-databinding."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-databinding@3.5.9.tuxcare.1"
    }
  ]
}