{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6f3d9d1c-5e0b-5426-be1d-9ea1c1c87735",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-security",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:111a7a42-8205-527e-aa12-79a9a3e36684",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc85b97-bef8-5b1a-8b40-05f22b92bf07",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a87ef27-374d-5935-ac71-f3add779e703",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e13b6104-a820-5475-92a9-070c1db04ed9",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ccc5ea42-1185-5b0b-b77d-d0ec1eb163a4",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aef4668b-7db0-52e5-9dcb-b1cd98c72b18",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d48bf7a8-7fce-5243-8933-4b609c0e8a6f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45df65e1-552b-5b3a-9bb8-f27d95b29ed7",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:142c705e-34c7-5a33-ad9c-36416e5eeed8",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb182c5f-0d71-57e9-be80-5fa75509cfee",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b189457-cc16-5f0c-9e00-dafc161492e5",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0deb469-557d-5a4b-95d0-baaaf398d648",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9409da3-c5b5-5290-9c1b-be702fbc5433",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f8ee1dc-a875-55a8-b835-b902325b7261",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ca3c595-d281-5c43-a0f5-c46908245491",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a25768a7-c091-5e7f-8d2d-db88a3d6af60",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d51658e4-6d9c-53b3-9091-6cd755c5ac61",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-security 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:959ac688-f4ce-5581-9806-97fcf79a7f0f",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fca3a80-2623-526d-b960-62cbe130f423",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f08c8c8-d7b3-52f2-84ea-a44959113a65",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c38596e9-77c2-5ca8-9f96-714dbbb4f3b2",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6585097c-54d1-5c05-895f-4e4cc7f345fc",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13fdd61c-c91d-5272-8094-020c3d8ad2b0",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef59f507-a828-53db-9432-9a32a76b3e04",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d46c988e-5788-56cb-965e-b7288ddb4bcd",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e15643-2089-523c-b1ef-1847b91b9390",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-security 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:790d55e6-8aa0-5c0e-9107-27f71beb5035",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391f0da3-01d1-5fa1-a37f-72d8e4012c18",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a285a15a-398c-51e3-b24a-c619b3b2811c",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a25f989-0f00-569a-9cd3-8705298ae4f6",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-security 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8cd0e32-339b-5c01-aef0-ae161a15fd1e",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a8645f5-1073-5fa7-9c11-030b41fe7181",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daef8aa1-ffb4-5f99-b033-9b6ee4c15e45",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f734d52d-1083-59a1-9ef7-6e6beeef286b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-security@3.5.9-tuxcare.2"
    }
  ]
}