{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:518451d6-8c14-5375-969d-7a495a80a751",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-ws-security",
      "version": "3.5.9-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e341701a-a318-577c-836c-4dcf08ef3729",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abeaf5e6-b5e0-5c30-88f2-90331be869b8",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d512d84-e529-5a1d-937b-3d8accc05203",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bb27134-aa36-5e3e-bfd2-f40827aea162",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a598eca6-c97c-56cb-a3a0-be2d4067e2c0",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb439240-16e2-5e89-aa66-ad02013f23f5",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb1f0f6a-c0e0-5169-ad8b-0e110e1bd707",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01369c76-250a-5a27-81f0-20dcb0527c88",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a5f41bd-84ef-5657-9f3b-9d72c609dae3",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b6f9807-9b7e-55c6-a373-db5ee3bb93fd",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e511f3fd-4684-5ea0-9e38-8b010c142b22",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca3dbbf6-0772-5f81-a952-248f306d6421",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eba2359-10d4-514f-939d-704073d63a75",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e9b3123-a27b-5648-bb6a-07b1b7bc2ab4",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1128b9c8-2fad-59f1-8c9b-114fd538230e",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5fee7c1-78f6-5bbe-9180-c4e96a3b0cf9",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d7a998-f013-5e5a-bc0b-ff9ed8003204",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-ws-security 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f6d8948-ee78-51ba-a1e3-0e4d635081f8",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0ce1b3f-eaa0-5ca1-847b-e50a412f39d7",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcf69b59-eb8e-54dd-b906-dd4376317c94",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44f064e7-0a23-596b-8d5f-82ed37002ea4",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:521adae0-9e98-5637-a62e-cc5a4b65e2ac",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f559ccb-8927-5aa9-af0c-c622973b0b02",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:360f7b20-1fec-5f00-ba8d-1d64bf2014b0",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad637571-fd6a-52b2-a595-9c0aca5d4781",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe4435e-1a6e-5aab-9f8d-8b4c6b990288",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-ws-security 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:730159e7-d3e1-5ca2-b65e-44cd746b7179",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:562baa55-582b-5243-81a0-63c3cd203410",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95bbb8e8-cbf7-5f50-94b0-b543140aaafe",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da6d01ff-5e33-57a8-827f-2ef29740d8f2",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-ws-security 3.5.9-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f999532-c371-5448-b713-6e02886de97a",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66760341-1ae0-5c98-9924-a7f8214d1c88",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:899c3fbd-5488-50d8-bbc5-89d20a884915",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:041b1dc7-5f95-5f78-b284-96e96ecfa5bc",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.3 of org.apache.cxf:cxf-rt-ws-security."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws-security@3.5.9-tuxcare.3"
    }
  ]
}