{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:163b3733-611d-5a55-81d6-d30af9a649bb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-transports-http-jetty",
      "version": "3.5.9.tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0beac21c-3311-5df5-a0a1-bb5bf0f393fb",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48ea2202-b4c9-521e-8697-c24f7c1637d3",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26f33d02-8b0d-50c4-a960-565f38720b0d",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9678481f-de84-57f7-8808-5d9ff8b4e28a",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c367339b-f375-516e-bc7e-0c45b5bc9bbd",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff2b0640-15ec-572a-b2fe-78880cc0d6c3",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ddf77a3-32c5-5212-975b-c47df1c1ef18",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7de00f1-c5bc-52c0-8bfd-32274abb04c3",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83ad1bd0-a037-588a-9a4d-841ffa865a55",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfbbfd55-142b-5cf0-885c-270f1e9a2c7a",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af2837bc-eab8-520e-96ad-d8853966a91a",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fbb490b-8226-550f-8dbc-f78400e84d50",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bdbd7d8-776c-58c7-9fda-2903d4069994",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:613a0e3a-eb70-51b0-a5ba-2eff189a367b",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dda24a9c-9092-5ffd-9a72-1f3766f449fa",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3cd736-7a5c-5be2-bea9-1c8e40fd48e0",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee80f240-9165-582f-81b8-18b846ee2e24",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-transports-http-jetty 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53194e4d-66a1-546f-925b-d66ceaf80446",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5daf1894-a9df-5745-b0b9-663c57e8e7a1",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26c74270-1f7c-55f2-afe1-e05832b2080e",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:767a02af-83a0-5156-96cd-932b8478769c",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cab98a42-61b7-577f-857e-039d98cfd938",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2acc009-dde9-5a5b-97ae-15e95d820f98",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84316a2d-328b-5de8-a2f3-a5a83d7756ca",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78357e6a-ca54-538f-b048-cb711b7e96d4",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d4102d9-d643-56ce-8e39-433e64780423",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-transports-http-jetty 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a03694ad-111f-596d-bf94-252fa9386b27",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:357027ba-c695-56cf-bd1e-90258075aa27",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d407e1c-70a8-586d-b292-3255b38246bd",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:509cfb54-e1b3-5404-8b9a-f9d23b949a3a",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-transports-http-jetty 3.5.9.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d71502c2-6993-5fd0-a9af-f990abb85e0b",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f708494b-c08f-5484-9c5a-2e07380e7f07",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:415ac16a-60ee-54aa-bad6-d68386b08c9f",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e89acaec-9317-584e-a2d9-7e79993641b1",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48913 affects version 3.5.9.tuxcare.1 of org.apache.cxf:cxf-rt-transports-http-jetty."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-transports-http-jetty@3.5.9.tuxcare.1"
    }
  ]
}