{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:0071027f-992a-55a6-84a0-3eb3ceb6db39",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6cb47b05-2487-5237-accd-90e2ab4222b5",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ea2e8ea-2d74-5858-8880-6a2d5ed388f4",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5855bb63-d9bc-5e9a-8360-a2c08bb18df3",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e73c493-fbbb-5d4a-bc55-0b44f492c7c5",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31add2fa-2b6e-5932-b707-a27c7b57ba50",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:518945c2-ab9b-5c7e-a5a0-0d0ce4445d62",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2edb6de3-849e-54df-8fb9-4290de01a41b",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6395398-b3fd-593a-9356-924859b78ac5",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ddcdf40-3638-53a0-933d-4171e3c4bc07",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8746593a-9927-51e4-8d5c-6ee55c1e57dd",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8ceb1a4-40ec-55ee-a1c4-af8bf4ae78e9",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0295b817-c4b9-5216-98bd-1e944232b3f8",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1851999-b73b-5e00-867e-a31913e79299",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d63f96e1-1e51-51ca-af75-15b680a8ffd8",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:effc6247-6e27-5ec4-a8ab-4ade8873366f",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c23aa94-3cc6-5981-9341-1605afea3b73",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd320dec-0191-5535-a0d7-05eef32df9fa",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ef473b4-20e2-56b9-af35-e05251cd7a01",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c27ea409-2aa2-5bfd-8e0a-f3bf80daa533",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dec61c01-018e-5272-89e6-2d1bb0435cf1",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24a5632a-4230-557f-ad7e-9354b111cadb",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b3a9138-94d1-5013-82b7-372cad100ba5",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee2899a8-c14d-518b-9b94-0225ef4ba9f5",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f0adcb4-4b65-5b7d-bcec-1ed468126ba7",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2923dcbf-d5fa-5f53-b660-63b85755a6cf",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a13c0b3f-66ac-566d-8263-66efb8098c2c",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:597d9545-85a8-5029-94ba-6262113a6f15",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebc3bbf5-9329-5112-b2d8-3f5a75e48a55",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41dae669-e043-58cb-8521-63d10d76a4df",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4444e0f8-7775-5001-b5b9-35bea5384ab9",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16ede45b-aa98-5b6a-90a5-586c7e40c2f6",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d87bbf3-c7fe-5722-8a57-dceae4dca3b0",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c309f643-4f66-5c12-b576-be89f69b598b",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:555ad846-bb93-58a2-98f1-d62ce6e4086d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-rt."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt@3.5.9-tuxcare.2"
    }
  ]
}