{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e4c1151d-ed27-5c8b-b5d5-36883e2b9bb5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-features",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:330d4171-1e28-5921-964e-8b2e74d3f811",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2d716ac-f67e-58dd-b3b3-953e297986bd",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2e99b9-7e19-584c-a441-c5391d9f2962",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:395d00b9-4ed9-5204-8ff6-35ec28d3aa57",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db0c15af-f957-51ff-98a6-0e950affcea3",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cbeeb32-1e84-5e4f-bfef-1559494e6819",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bf4ccf7-3a56-5285-95c5-6f9decf3ce97",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ecd0988-7584-54cd-b3ef-77dd34369fd1",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8283c706-be62-5554-9828-4be37b1cd01f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6646f09a-6097-5462-bd0e-db4e3ac1c4c9",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0050cb5-b5e2-5356-9d81-fb2b2a02a3a3",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9a10261-658d-5ce0-ac25-0211887dc84c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e151b8ae-04db-5fcf-a74b-43121db4cd3c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce1c2fd0-ff32-53d1-83fa-254fc8d8315e",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:500af5a7-8fc2-5b5d-9d34-8660d8450f44",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30243c9b-7a55-55c5-bcbb-6463855fa65c",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa484737-7a78-5601-b21d-7e1de4cd82b9",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b089ce1c-14de-5fbb-97ae-8440741d0c56",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b40472e3-af55-55a3-8b30-a9ccb31e6fc2",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda86419-4e48-5641-b3d8-7514341bc6c0",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:025a8b6c-919e-5dbe-889c-8aa3f103cc3c",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e03f7b0-da81-565b-87c4-c0cf194b1dce",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e6c1ad4-2677-54f4-896c-718561f1c906",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9912855-da3c-514f-9d30-40264b4669b9",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc6d17f8-756a-5fb7-89c8-d0ca468cf9b2",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0454145e-7c07-5099-92e0-b8ccabc374ab",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a9bfffd-b629-50c0-8bbe-09c1322f6414",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c3c025b-9610-54fe-a067-bd3420111552",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eab4e509-156a-5ff4-bb05-79bdeb384cb1",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffb4ac1f-2391-54e5-b819-29a12805df78",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c8b11a-d215-511c-9de2-b3b88ba665dc",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011cde6d-558d-52e0-8ba6-14f1cbcbb00f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4df852b-87de-5b01-afa2-b1379ad1bdd9",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2baebfad-3b2c-5c22-99a2-695d246f4f18",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9.tuxcare.1"
    }
  ]
}