{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:faad484b-8726-5415-b16d-59b14268a3a5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-features",
      "version": "3.5.11-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e3525d51-0e2e-5b3f-a82f-fd0f44f2bb23",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d878343-1588-5d9d-ae54-0e66e9b788be",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe296f57-3f1d-5076-8271-ceb01945059f",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb6b68bf-c15d-5301-adf5-82966d37d38f",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:378a9182-b32e-56b6-be8f-087e7bc5b238",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a773dc61-2198-508a-8ffc-47bb7ce273a5",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4864df2-9b52-54d9-ae3a-622bbad40de6",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c81d037-d474-5bdb-96f1-ab06b7b8fead",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52a22110-cb61-5d18-aa71-df3ae4595edc",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55feabad-8048-5207-84d5-13745fb9c2fc",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a8cfb99-f01e-50e7-a337-47b518ada8c3",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9fe60d-7e3e-5498-b8bb-e4d6dc77aa10",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7da60a7-a86e-5568-8fdd-fdb691f90e11",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94039abe-8106-5b52-8875-a45b82c4c616",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b13ba648-b23e-50c2-a3f8-8d8fed0f3f21",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50d8215f-019c-50b3-b80b-ce07b40a2c43",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d185925f-54cb-55ab-9a56-688e4a6e4eba",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5be3b13-4729-5c19-8ff8-17ef9e2925d9",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04752f52-24ff-5696-8a7c-2e05789b3622",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d21cc993-1973-54bb-ace0-134b631bbef8",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7834689-5446-5782-aded-16fa31cdcd2a",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:353db50e-0471-5a54-ba83-0953c2cb1a8c",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9ac152e-b5aa-5f34-8674-71c35ed408ab",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ad3e438-219e-58c5-be77-709f70b9645b",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acad2d00-419f-5743-894a-34cb9a913467",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:126e6698-cef1-59d4-a296-f971c85bb586",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-features 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8a19b25-eaae-5a5e-ae13-5bb6fe247308",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31ab73c6-252f-5f5b-88e0-97b1d39db717",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-features 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0fed0d3-043a-5e91-8cc2-6db56bc652c8",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:571c09cd-93a6-54b4-8823-3edeeb311309",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-features 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d319eb23-d7cb-5c06-94c9-3157a27f39d3",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4af1dae-8a5d-519e-bf88-a493fda34f60",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.11-tuxcare.2"
    }
  ]
}