{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bbbe1736-933f-5a69-b637-51c3ba52e331",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-javascript",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:33dca845-1740-5a0f-8941-5bbc9392db0e",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b13be71-0e5b-5349-bc7e-f2a766a0dcab",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3020a86-014a-541f-8f6f-b5300ba8afbe",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:594251eb-7f44-5434-a45e-66017f322ece",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:154a285e-1735-555b-b682-92f54f41b136",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce652801-8208-526e-9aba-c7a0991e81a9",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1796bc2e-3283-58c4-ba09-69cd8bcfa243",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00269de8-68bf-517e-96f9-c610b08868df",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f584d18-100b-5b7c-a7d8-1c93df235345",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6617047-ba35-5d33-9a90-68c01e29cd08",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c078cec-b7da-5999-9dc8-2cd14a3f5173",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e577bba-04e1-59e5-a5fd-c165634c55eb",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6218a511-978f-5e25-940c-4439da34187a",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b139baa-ca81-5eee-a9c6-1a07009a78a7",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11572225-738f-5ae4-8144-6ff38367d01d",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f981990a-5a49-57c1-8c35-a447ad3244da",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7da6dc7a-27be-5e35-bd53-de98fdf3c325",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c425b05-6add-531f-8c0e-40600c3c12c1",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f124a32-320b-55c3-8f25-3d39381d494a",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc880594-548c-5280-810e-5bed46a51f19",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9627c1b-dca0-5d55-b67b-a28eea2bb5d5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4e7b9a-cd1f-596f-abe0-68b9876a95ef",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dc4e1b5-232d-5519-bcde-d7172f7c2404",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d8ebf9-8a50-56f0-8ef1-38499be80cbc",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57fe2d95-17c0-59f2-8618-2c552d0e3ec7",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39f27eab-7d39-58f2-9757-1ddb2120293d",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-javascript 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1d68392-2313-5b19-b7b8-fd170ef5eeae",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc1546af-e025-52fb-a130-de81660cf0af",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-javascript 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:999c29b4-e076-5b12-941a-8952022b816f",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba06d69-47ee-5b1c-895d-75e85073c023",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-javascript 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3047f089-4ee4-51a8-afd6-92208dce4124",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72573b13-221e-50ee-9bb1-319c3c7dff3b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.11-tuxcare.1"
    }
  ]
}