{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9b65bc8e-94e2-53c3-91bd-75f5a10b0b58",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-runtime-javascript",
      "version": "3.5.9-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cf54fd98-cdac-5c7b-bbca-93d9cfca60c5",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4743435-6c3e-5450-b5b8-e3b1800e090d",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a443e8-520c-5b00-9b21-dfba52fdefc0",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:701ebd01-544a-5e7f-82ff-de57f90908a5",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f54b31a-b4b8-5d85-94f8-a1864c76ae5e",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c63949f-30c6-5e8c-bfc2-94d315b019b8",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5bbbb62-5256-5529-96bb-c0212c2f7871",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c40bfe6b-6bc1-52ce-86e3-913f5067ad0b",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b81b66af-b1f3-5346-9b11-2fff30ec5fc7",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85f95a47-f1b0-55e9-ad89-0a485e0b16fd",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1663d726-82ad-567d-9294-54bdb01f4059",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffe23584-af6a-548e-9e4a-1af1309e8a0e",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f725e0bd-b25f-56ba-be18-3087518e2ec7",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91b300f8-8710-5b1d-9833-7eca2a9ef352",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e36024c-73a9-59ea-be3c-804e6b0bfbe9",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6927693-545a-52f2-bfbd-30eff558e282",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd3d6f82-b19a-5b37-91be-8674bb31a50c",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-runtime-javascript 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e1f765f-78a0-59a3-a759-36e98c005b7a",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfe25327-a86c-5c27-9410-c7c7b72934ae",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b6bda6e-f22d-5416-a2db-d3b059bd508b",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b35ec3eb-cda0-59be-901d-39b253eda2b5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45b32019-ac86-5c5a-8626-c20ab1363554",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd1fa840-571b-5a62-bd85-776ecda74440",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce0d885c-fb28-5cbc-98dd-8ccc2692ceaa",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:600a9c25-9bf7-52d6-893e-600478db3dfd",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3e64d7e-a7eb-54a9-bc15-8b24acee31ea",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-runtime-javascript 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fbc3720-cbbb-5e14-8c2d-7d32d6f4e8d3",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20c8a1fc-4077-5334-8d88-fd87200312ac",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e5cefe7-0896-5718-a409-67645db77889",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2995243c-f9c8-5889-84bc-745aa18f34b7",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-runtime-javascript 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2507647c-d8f1-5450-83dd-df25630064cf",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a944968-e548-5727-a4b0-2d37697ff6da",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:372e58ff-3114-510d-a28e-2083ba120869",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a2a9e46-5e3b-54c7-be67-d93000b0540b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.4"
    }
  ]
}