{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7a184bad-8ff8-554f-8837-98adfe421fbe",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-ws-policy",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:997dace4-8721-5dff-b814-46fa80e574a3",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:767fe31d-7a66-5193-a0c8-f43752319cb6",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d115b4-22c0-5066-bde0-d3fc65ee4d35",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8036bffb-5d3b-5aa5-8656-30637ae9baa7",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11c62ac9-785b-5162-99c4-03e1b5ec3c9a",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66792435-9e48-5ea4-aef6-6e1c1346327b",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:675efca8-3f95-5d6d-9696-7d49a6e46659",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c01ef9-6707-5b47-ada3-ced1939d0b4f",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:193af188-ed6f-5ab1-9a19-156a5c5b4d1b",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0dea430-ae76-5236-b9c6-641ee60874e7",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dd15a6e-2137-51bb-8049-8ba4c636e5da",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:322f0d41-9b27-56ae-a53b-5eba8a9db8c6",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f168173c-4263-5180-a9f1-f4f5e7d24cb3",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:991e67e8-4516-5b35-acf9-c98097c3be89",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1a5cedf-6d68-5fce-8ef8-9ac468e40acb",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27cd8f46-0341-5683-a1eb-a9c19c57f51a",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80babda6-d96a-5a5e-8ab3-8a79d28ac10d",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-ws-policy 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b6fe6f-3355-5fb8-b96b-f3d6cc13fe87",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0428246-b5e1-5ba9-8d53-28811e78ebe6",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db18335c-c357-5677-9551-28f6274fc8f8",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a31e577c-0e32-5eee-86aa-7113f886ef56",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42e4a634-dec2-582f-9066-b6b5062c1111",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4807aec0-2d8d-5bb1-a9c8-6c43bfb9c680",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a0467ed-73c0-58b5-8480-049e04b4f030",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed554f83-8e22-51bc-bf92-f402b6e9d78f",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d46b6173-4d24-5dde-928a-9dc315aa621a",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-ws-policy 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c887bba-7789-53b6-b146-d2eba62c454b",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67c5d85f-0fbb-5d99-b549-828822f5c8fa",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70191cea-e220-5eb7-95df-cb89635d2003",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c958f6c-b0a1-5af5-b2c6-8557ed4d6d0b",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-ws-policy 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd27305-839c-5f55-bc51-f56a970d4846",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20c4fdba-ac26-5be5-aea2-b13a91f17d3a",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c900aeb3-da22-5f7f-9d27-39af43bec6ca",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a634350b-0c78-54ea-afba-f43e2f50c48d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-policy."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-policy@3.5.9-tuxcare.3"
    }
  ]
}