{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bed0d98c-b5b8-53d4-86de-b956aeb69329",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-ws",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:46652963-7a2e-547f-bf79-0a3f8bd8f3ec",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c993740-294c-5d51-927f-43c8b863e02d",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81dc8f76-5b1d-5ef1-9e19-4a23aba222df",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13388bd5-47d8-574a-91fd-84484e6ac711",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d27c054a-2cdb-56f5-bd5c-2bc42e3abec8",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05689dee-b245-5738-ab2f-d6324d5c3556",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4823a626-2e44-5bc3-927b-38a993a1ddc4",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28609253-c107-5b53-bbfd-c0eb4a4bf627",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8422cd8a-1b58-581e-a93b-6f1c7b72acc0",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf35ec64-7e9b-5ec0-b7c1-65e169528306",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49fbacca-7c39-5897-8c7e-1bb70bcb72c2",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8547c55d-6cd1-50e8-a442-8a1221fc5a43",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:530474e5-6c44-5a5b-896c-96e990ce93fc",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5577b553-142c-518e-b84e-7eceb07ff31b",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09992fa4-7c0b-56c9-8e0e-9d76fbbd199c",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a838ae93-f87b-5856-87bf-40f139bd03aa",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ff7c72-1f10-555c-b488-6c7b7eb69848",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-ws 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d2fb205-d719-5d9a-a142-06d712df8e93",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57b4e447-071b-58ce-b0ef-9a424730f509",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b47d70a6-9d09-5526-a07a-68c1c0f0336d",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85251a6a-4e30-5489-9df3-b048b91c3505",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c245a17e-f349-5a54-b1d8-6685164633cf",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecce16d7-ff65-552f-bb8a-618a0889413c",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba88a40-2730-5a11-b391-4f336205267a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16795de3-60cf-59e9-98d9-8aecbaed15b6",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d160503b-b0e8-5f36-a2fb-75041f162c7f",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-ws 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ef7f4c-5443-531b-ac9b-7fbf22f5b0d4",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:090cdbb1-28dc-58b1-97bb-392c2fd41f57",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d537366f-407d-57a3-85f6-64484b807b92",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90851334-974a-5cce-9788-b406ef40c01f",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-ws 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1a78ebb-e090-59a4-b9fb-de1ac742f8c0",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:350aba70-a854-5ac6-87ad-bab5b34d09ba",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a1abd7c-87e0-51e3-98b6-bb32a7adb48a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:931ac9ec-0d82-58a8-a502-c32f395e4eb6",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt-ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-ws@3.5.9-tuxcare.2"
    }
  ]
}