{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e3d9d146-97d9-5263-8fc0-27ec1bed7dd3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-security-saml",
      "version": "3.5.11-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c9b811ba-283c-5ff0-ac22-2690c067d925",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa9f9ac2-ad45-56fe-aa28-6db06a494d6a",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7730f0de-88ce-5506-833a-0dcca5653aaa",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c54837a0-5538-54dd-aac8-3c5b284efb16",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83ce70cf-8769-592f-9695-5ddcc03c35bb",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72099b45-4163-57f9-ba35-ffa46f1c4a60",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3bf30cd-2349-5197-bd49-706f06b9cb61",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75e0f3cb-6fb6-5947-b6e8-09d64b3eeaa3",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b4c551f-1801-5d43-be27-7c93576b1c2f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95c3d90f-9250-5f60-a1cf-2b1df49c41bb",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:413fc32f-ceda-5fc0-81f7-0658bac2d420",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55e5d176-e178-52b9-a6be-acd111a36037",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feb01bc0-523b-57e6-bd5e-8a7bd44c8dfb",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:834ecc32-f210-58bb-b80a-d2a3a4b1b5ea",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d084be37-f3c2-5d39-9078-ac10c83eb636",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e479330-4a99-566e-bb41-b913dee9e57b",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06feb5fd-74cb-562c-9509-569293f0ca56",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3979d920-5dad-5038-960e-e286649ea889",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf51bbe-7171-510e-95b9-b8f118da485c",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec585526-d5ed-5341-b01c-8c063ea6547d",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec3fc8a5-5bb7-5194-bca8-6345fa4dca8f",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aa2e298-4aec-51a1-80fa-03d10d0a8bc9",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ca300eb-7966-52fc-ad0e-530f45e34406",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79453b0d-8765-5fee-89d7-abc098182948",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8813ed90-8f31-5284-956f-620f474467b7",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6294fbc3-66b1-5431-b98b-5a0331ac2b49",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-security-saml 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42c61dc-a642-5d08-adc9-6f4961224391",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c56eac2-95d3-5a41-8c8e-3dfc023880c7",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-security-saml 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42373ffc-b58c-5516-8b5c-7b852c550d46",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0ecab26-d047-5cb0-94a9-f9ba6a799ba5",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-security-saml 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ebf4a5c-1517-5e7a-894e-66404c982239",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c34ea726-8258-5f98-a6c7-f3738ea59610",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-rt-security-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-security-saml@3.5.11-tuxcare.2"
    }
  ]
}