{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c85faf0b-b0d2-5601-a938-e3a3f52feefc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-security-oauth2",
      "version": "3.5.11-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dfb71b37-5325-5e02-b9ab-e87bfc857842",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dc278f8-5f24-59e2-aa55-0e7cda22500f",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df23507-0f44-5310-8ed1-f7c85da5eef3",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd36681f-fb09-5fd5-8943-786fbef06fee",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a81eba5-80d3-5ad1-bfa7-d0ac1ebc180d",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0110768b-2c67-5ea3-a0cc-8cad6d313b12",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:692b0e16-f62e-5d30-b90b-abe9c999c4ab",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fce196af-3f5f-5f42-9346-4a9119d272cc",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c2abaff-7554-5bed-b093-65c4edcd1f8f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b40b6bf-100f-5388-9d72-3b183d4b25e1",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f056921-30f1-57cf-a507-4250b8dc4895",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b33c661-5fc7-55ed-bc6b-eb992604ae2c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbafb9db-e356-5336-924e-7421493050dc",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc21c03f-359f-5bbb-87bd-c8046b2c568d",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5356814d-e6f7-5c1b-8c03-e5d044f763de",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22076600-0f43-5536-a5ee-15c59ef4bfad",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fef54444-747e-5d2f-ba50-34bfaec7ea3b",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abf610b9-6ef2-5a8f-87fa-8d2c5bbcea37",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db95048b-0ff5-5932-9d2d-d7247966df37",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65cdc223-a698-5697-9ec5-945aa6f8df74",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:372adf42-a3f9-5fc8-815d-fb77a2d15e7f",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e561a14-2956-5a2a-88c1-f0590bbf2ee1",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3805ac34-05eb-54d7-a5e1-35cd0d5b169d",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48a6e9a2-df08-5a66-adfd-544c78bb25b9",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f77aaca-e7f5-5245-9cc9-216a585b6a53",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86bde38c-17a9-52d9-b864-a3311766c31a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-security-oauth2 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c799e987-f07e-513c-90e4-292082c1d4b8",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e70f748c-8327-5202-86a9-9cfcbdc95a88",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-rs-security-oauth2 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3c8ffb9-0f47-5c29-9d4f-300555e4e001",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7381634a-80fe-5ec0-88c5-92e5c93f7eec",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-security-oauth2 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:938e3555-f3ce-58f3-bd0c-bf10540307fc",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c8df52-c0f3-55e8-8ab6-9356b2e29e66",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-rt-rs-security-oauth2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2@3.5.11-tuxcare.5"
    }
  ]
}