{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:44a74b29-a888-54ae-a71d-8a2dd5ea6df7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-security-cors",
      "version": "3.5.11-tuxcare.6",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:533d19e5-62e1-5863-88fa-7d6787d73a88",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83ddf061-9eeb-50dc-adda-8cdd68286856",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:834307ec-49d9-5e48-9ce2-633bbb0d3d32",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fd96bca-ac0a-5e35-b2cf-6e07792a5604",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b0aa4ad-05f0-5c21-8921-2e5837254a9d",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f830223a-4163-5321-bdce-f316fea6f51e",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70efbf9e-67d7-597c-b79c-2e91cb45b594",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71e6400a-8afe-5cbb-98e6-90368475e641",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcd8c67-bb41-5cad-ab26-b0d88baa62d3",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3b0fbdb-5cb6-5314-886b-94361b4748d7",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baee8a5d-67bc-53d1-819b-96e2bc7d881c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc1dfa0d-abc5-5c0c-854b-c34a38fbc2d2",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c29d56b5-ec62-5141-b3c4-8be2b4403ec8",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22b53839-628b-5361-a25e-7aaea8f6fb0c",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aa1f597-af00-5a15-8419-1b8aa23f0c6d",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:321429aa-1d82-50b9-8b53-3550a55db1a3",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28769632-d0f8-5f49-b246-b087f3e16287",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c93ef1f-0a35-5813-8bc7-41cf29b42368",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77398158-4063-5cd8-8ad5-a5b6d2c3cf00",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc2cd2a0-8248-565e-99bc-06a2be88e567",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a54c3be-d3e3-5e48-bc7f-c18e4095b324",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1de7f5fd-1c0a-55fa-992f-21ae0789bb2a",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cedcd6e4-cef4-52dd-abcb-7b7f4b2bc7a0",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:addaaa26-5f0d-5bc3-8d5d-f6a716eb78c8",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f9652e9-f931-5ad8-98ec-682ffbe8633e",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e4cc656-bfbb-5e27-b784-37d951186377",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-security-cors 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba9aa9aa-8241-5bd2-b10a-8d6803b8d75c",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4cbabc4-29f3-5173-9d7a-4e2f3ae16f32",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-rs-security-cors 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ca89470-105f-55a1-a433-d5025f434c63",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6014748-d6df-5435-84aa-c42768d15d54",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-security-cors 3.5.11-tuxcare.6."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f815b2f-8e15-5462-931a-d2d1de6a8574",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f167fc6f-9bc3-5ec7-b2d7-302718e1128c",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.6 of org.apache.cxf:cxf-rt-rs-security-cors."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-cors@3.5.11-tuxcare.6"
    }
  ]
}