{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8a2cb701-c8d8-5878-a5f9-a3837dc2db53",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-http-sci",
      "version": "3.5.11-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8c8b6dda-16d7-511a-95c5-8df7487e833c",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45c819b9-adcf-536d-a84e-3bcf89468f98",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98a0acba-6e43-597d-9860-262a725a1431",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5973b812-3216-5b61-89ff-d2f56024a6fe",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4510911-314b-5f12-b524-8e4bb1fd6408",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ecf5407-36d9-5dcb-b37a-8bed20fe5475",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:013ab584-276a-599e-9921-fcd0a7b54eef",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55c28f8f-cd2d-5b8d-be7b-0a2b160177c1",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6055ffc8-3712-5e13-b97a-b25b18dcae4f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49703d9-5061-5c9d-863b-a762ab857a47",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f96478de-98b5-5761-a08f-354bb2a3b933",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a07e57d7-0f94-5db5-b884-8fc8cb0c7b2f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6af3892-8494-5c2a-8c4f-25407f968168",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:071ba361-e8e8-599c-a6dd-b571156c9b68",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c14b2f5-ef34-521a-b807-9ef85a20ada0",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb801a65-9e33-556d-856a-d5f13b22b242",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd07fc7c-227c-5d27-8a9b-24b54f390f58",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:382f562f-c09f-58b0-9a55-b0afd866e6e5",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635b2169-e229-5b99-8e7e-4e07b40deecc",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2e5f7f5-8d01-52eb-b626-3ccbcdb879f7",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62155df4-2394-5373-a9c2-ed8e5f854116",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d62ddd0f-0e2f-5ffe-8fb5-069660983628",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ad20f05-30b0-5ba5-9270-8ce83ae76454",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e52d8a22-aad0-5b8c-8e44-0206264c8f25",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6edf396-ba84-5b17-9798-a9be74910e32",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eee52af-d7a1-5958-92c7-a72fa7acc206",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-http-sci 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5d3a397-59db-5921-ba8b-ec4f18998a28",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:218e304c-a2ca-50f1-8018-b38cca4d8bbe",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-rs-http-sci 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae1005e2-60ce-5722-8499-330d203507f4",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c99ef022-8aed-5fed-8869-9e0f8a31317d",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-http-sci 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ccf0c32-23b8-5644-975e-397724ec4a8a",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d8eb3e4-93af-5c92-b2fb-8e62f5eafc30",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-http-sci."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-http-sci@3.5.11-tuxcare.5"
    }
  ]
}