{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2a85f526-8133-56b7-9b58-ae735220efd7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-javascript",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4a48d1dc-d4b2-5765-8c07-295eb0853d4a",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96affa72-5f02-5446-bdfb-f440a4d8324e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d41bbb31-6077-5a71-8ff6-b4dd8b761819",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc179249-7dc4-5c7d-b1de-7b8d87a298e6",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c52c0ff2-e788-5af8-ad02-c71804230435",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a19cd2d5-696d-506c-8f4c-e48f7593e143",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17a496d0-73da-5725-aa28-f472c71bd920",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:650352a7-7cb1-5c54-b792-dd89084f246d",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b144dcd6-0af9-586d-967a-bd586e1ea9e0",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3d6aa44-754b-5c71-a6d7-2aff350aca5f",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:752794c8-49aa-5ae2-a1c8-4bf504d4737b",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:382e1760-ccf4-5ab3-8d30-17604eb84717",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d87bfa75-6c64-5a6c-8356-4ad4dd40bfae",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01718797-4583-5764-9c32-ede4f129efcf",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b1eb8f0-b3b7-5508-ba58-28fe1d26595e",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83cca205-44d3-505c-a112-4bf4b2f7cd81",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afeca889-02af-5e15-8c30-be27dc007547",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-javascript 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49018c69-3299-5750-ae5d-0286a1cbd1ff",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eedfb38d-6edc-5a1d-8509-8bcc656d0737",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c07b87a-3acf-5f80-80f6-36397fb5ad84",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a5aff02-683a-5f57-b69a-2af62b2bf62a",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93cec2ef-612b-504b-abf5-1dddbb672221",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:989c3bb8-98ea-5474-bed0-050424ceab15",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfcce32e-da8c-5873-a000-48474a029bc6",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb11227a-61c4-5337-a30a-699ec0e77fd2",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6457dc1b-1dd7-5324-a23e-b4e21c538fc0",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-javascript 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de31d62c-8d92-591a-a966-109452ee7252",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1961bf9a-ad22-5825-9058-b87f65f1c85d",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ba9d38b-b9a8-5904-a6a0-431af2fb4b39",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fb85b77-abd1-5dc6-b9c8-4f0ef1d09aaa",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-javascript 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9928ef95-72f7-526d-b4fa-5cb20fd38c2f",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b863aaa-4d3c-56e6-ba0b-59cb02645682",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8be13a76-b834-5bda-93a8-aa8327f16bb4",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cb2f829-b24e-566e-b2c7-e5da4b8f042a",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-javascript@3.5.9.tuxcare.1"
    }
  ]
}