{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a0998c39-3459-5a5a-8eb9-ce810da15e84",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-service-description",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7db7d511-5dd6-5d47-9642-b060e6498322",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2859ee07-78ef-557e-9fde-8ea46ef89a19",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:996eccfa-6ede-503f-bb0c-e4fa6d3c7c32",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b44fe79b-73f5-5fa6-802f-6a0b35e59b84",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60e9fc3-0382-5f38-a66f-a0cf7e827b55",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6162786f-f656-5ccf-bcb7-c6d6c7e532c9",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:112e84eb-ac7e-51b0-af9a-9f7790c06cf3",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0501bd66-3c26-52ef-8e1f-2ee36cd573b2",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060b7445-dfbe-5cf4-83b2-d652aa4125ad",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:588f6f08-d884-59c1-bcaa-d1848ab0c058",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30d0714a-d77b-506e-a6d8-72b694816496",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7e95520-03c0-58ef-b530-f26cb6725671",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e776bdc-22d6-5952-9197-1e6fb74154bf",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ac19e00-b4e3-55cf-aacf-84b29cc021fc",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2495b5dc-3a83-56c2-b0df-c81b3526feef",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9833c3-60b8-5e4a-bbae-c546ad0c9c10",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc19cffe-1e12-52fb-b1a5-946b9b728019",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-rs-service-description 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9ea6f09-441f-5dc0-b092-868d351baa6c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bb522e0-9e54-5bc1-8006-66b4e00269aa",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4079a262-77e0-55bd-bbce-17dcad7f3bba",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a2a5ed6-2caa-57f7-91bb-aae58d2b1072",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a6b0eac-711d-546a-a949-c57c6ff57d39",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad3fc3a2-360e-55ee-8aee-ea2e496d24c5",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e0d2c6e-edab-5353-8f6a-3fe808cbd1d1",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b23f399c-9647-5f24-908b-bcfe9a07a4f8",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e15c539-6164-51d5-97a2-55f814b2d1e7",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-service-description 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e0b0480-e578-5b70-b7a7-4c525041ffc9",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4b181ae-a9ec-587c-b50d-7a9d81ec20eb",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67d9f022-bc3c-5bc4-972c-a7619a6c16f4",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc41d6a4-a484-5c55-b991-773663eadf2c",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-service-description 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d4bcd6a-b44a-54d0-89aa-f0877cc7c2a9",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17352e7e-4b1a-5f3c-9cd3-8927a382e4e3",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0335515-bb88-58f9-8d68-dfe3aa439925",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef455f36-ddd2-5961-9686-d3f9158dca77",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-rs-service-description."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description@3.5.9.tuxcare.1"
    }
  ]
}