{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:92376d4f-22f0-5787-8b26-bff8ce50faae",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-features",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:85ca07ad-7de4-57e4-a73a-9f9842081245",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:281297cf-dc20-55e2-ae7e-03598487632f",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edb00ddb-bc2f-53a3-8402-3ea9f097693c",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e711061-9128-5fe0-b46a-01c688bd2acd",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81320ba2-0965-5fa3-81b7-23a0bd9a1ac0",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:150d4844-a624-5cc4-aca5-bc89fe14bf23",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55774e70-4ad8-5415-bbb5-21a0db11bf58",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d39a625-fd30-57da-bf64-73c5e0c17898",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc96483f-a44b-5a66-9f72-09636088cd99",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af45fcc2-4d6f-544c-a7ad-2e0a8c6879f5",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e13fc2ae-291d-522b-b5de-f3f600363c46",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67e42dae-6a52-5aac-ad93-08ec9c863461",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7f3e26-3dcf-547e-b1d4-222a920eaa1a",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fac0fcd-3008-5276-b453-27b05b3428f8",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed5b43e-d7a6-56e2-8ee6-e409f1c987a1",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df2d6cfb-d580-519d-a10f-8197eae59447",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d39fde2-ed1f-5a9a-a64a-83231da63610",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ce7594e-54d2-51a0-ae77-3d20c94a81ba",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a84b21c6-b5a5-59d1-b15f-37a8563c1a2c",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8592d3c8-34c7-505b-bacc-30e085c36676",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17d02418-c7ac-5043-af53-7eb40773160d",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbc8e5a3-f81f-5575-80a3-0210a0ef3487",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b0793f6-136d-5fab-8c72-45d9de90f00a",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:016d761e-2724-525b-ab89-fd897ead98d7",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7d19d4a-0c02-5f2d-b368-2a5ca863223a",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b521d4b9-9883-5392-8f3a-b3baa1d4ba69",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-features 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d611ab75-8a73-5480-9c1d-48ecfbc89fbb",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b5326fe-94d4-555c-bf34-3a61cbb9a960",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-features 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0673f764-2d0d-5863-ab6c-b8686cedf4d2",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7296518a-476c-5357-be2a-7535477bd085",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-features 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f58a95cc-9524-549b-af84-2c1c21d4ad89",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b3e81d3-8d60-529a-b33b-6ba894be07c9",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.1"
    }
  ]
}