{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4f41b9bf-65f0-56fb-b4fe-f98a586026b4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-management",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:234f611d-c798-5f40-8be8-0a878532aea1",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:579a54db-c783-5d13-9e17-d055d12fe7f7",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:000c2058-7efd-5bb3-b17c-bbe5a4d4ca9c",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8ab996-131d-5edf-a4e7-ddb3a03c9507",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f761248-b96e-5d04-a7b7-60105407e491",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:590abe67-1ca2-53e7-8e63-860908898ad5",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e833179f-69ea-51e9-8f21-00a31c9e29eb",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e275b048-8c04-526a-a2fa-a778b18e3503",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:359266fa-a608-5039-bd32-f772c8f9b0af",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48958e3d-9e3e-5cd1-aed6-8d221242b6c9",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dadadfa8-3de8-5522-b11a-142e233e2e04",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50664b95-8eef-5267-af59-21f836bab0de",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e683f4a5-d2d3-5439-845b-c3c2b669d230",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c66fa66-d203-5fb4-8c0a-0ee6c038fc26",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e2e5c45-2437-554b-a6e8-85ae5dbe1eb4",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67198966-4e27-5e02-adbc-b1322a926925",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b7580d-dcc0-5cf1-bbe1-3d887f96bda1",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-management 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253344b1-95eb-570a-b1be-b00d3fcb29fc",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eca49251-fe6d-538f-a682-c8a9e5a0110e",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45660b04-d761-5d63-8ab7-43dd8f9c258a",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0cef7a9-6f91-5164-8d97-96567fbda217",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2059194a-7d50-50c3-a166-97a44622b9a6",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74f26ace-9f95-5f25-9d50-aa82a0e56107",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:584e9113-86bd-504e-9c07-a8ea4ac0fb6a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c983b3ca-aaff-5ae4-a9b0-da9f5e28863b",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87eb7f40-c48a-51c1-a04d-7434eb61ad6a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-management 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0dbad3c-11ec-513f-8c75-59e22edda1fe",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:704a0f2a-30a3-54f9-806d-c9a47aed3172",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5119f30-c790-562b-9118-0f20b381e934",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c7931f-8127-5c2e-a457-3488a64128b2",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-management 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4da1015-94ef-5323-9c11-082b3bc9c6ac",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1eebea28-2e10-5c1f-92de-5aa7e661faf6",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:636d03ab-0340-554d-b29c-d68d09e58b25",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33173dbb-7737-5816-9bfa-0e1a4cf644e0",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-management."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-management@3.5.9.tuxcare.1"
    }
  ]
}