{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2a2f7558-f013-59e4-a9ac-7167d90f7db5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-features",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:09b75b43-3cbb-5fd7-bacf-02d421911900",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ff45b17-23d7-56a8-a21f-f7e38610662a",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00d832d3-301a-5dbd-8029-78020ce1577a",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4db8cf76-8210-5e1e-a061-b10ef49adecc",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a91b8e9-8f6a-51ff-9cdb-d9bbdd7cdbc9",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88a2954-820d-5bac-8b4a-fb10996ac081",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08fbcab7-0f3f-517a-a603-a99012c8a5d8",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8121877b-5b5e-5024-bb8d-31fad3b3950f",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c27c3e22-5dfd-58a4-9dbd-081946695a3c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfebb294-2f91-5af3-8920-8a90019a06cc",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948224ca-f6e6-5591-a25c-6203de9debcb",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58ebedc3-1dcf-51d5-b596-2ea76bafd159",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a6bee76-0587-535c-9896-2705b5bfbee4",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27a299e-3bd3-5d5d-8cff-46e918fd2d2a",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14db0e0b-7f58-5832-bdec-3d76c4afd310",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:234f2d8f-0df4-5eae-a71e-f290b1195300",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c63b1e2a-e72c-5f62-b32b-580b420be5d1",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cb654cd-bfc8-5b8c-8a63-18f45557c29f",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7da36bac-4dce-5729-bbf0-0375a764c195",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a41fcd-62b1-5619-b7c8-342c509ef874",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9806932-5825-5076-88dc-91f7cada0ac3",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f2497f5-c256-57d5-aba7-cff71bcd2577",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f231ceb4-c2a8-597a-afe6-65682faa83de",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a370bfe3-8af0-56bb-9f72-729be8b225fa",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3cd8527-4ffd-5292-b27b-156f356629e5",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d016cdd7-470e-5955-9e11-18ae3bd3e7d8",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aba1d48c-393c-53ac-b2ca-4607c56bfee7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:110464f1-4e7f-5af0-956d-138efa8ed253",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37f21be3-774c-5ec7-aff9-9ba3b7933099",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:444846d9-6277-5a60-9405-c8082c3e9079",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35c22cad-7c9b-554b-b838-19b855904763",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6077cbc0-4947-5793-9d8b-38362072962d",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1358118-455c-568f-977e-22dcc31e7639",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad5e4db3-ee66-5f62-84fd-78c6cd69f0c3",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.3"
    }
  ]
}