{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8825c30f-8b99-5d7e-8464-dbc2f1f63cff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-servlet-compatible",
      "version": "3.5.11-tuxcare.1",
      "purl": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:331e96f8-a635-5ab0-bd63-1f8a928116e2",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd25fab2-3cd8-5319-818d-d5d24a280fbd",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfe35751-a72a-5960-925e-86d1d3067763",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85af4245-87ee-585b-856e-9eddad14dcc1",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbab96a0-4191-5d62-ae33-dd04931f4484",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dff757e-c64f-5777-bc59-0afdaef889b2",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f86c18-f695-5392-ac6f-bf285f66cb0d",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea94e2fd-ca44-5141-8577-5fb8e620a352",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f51cf1cf-d805-55ba-a7ed-ec87e4868ecb",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d60f3a-c93d-5c17-8cde-ec0207e503ee",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b61e863-2e9a-5475-b304-04b8dd3893e4",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57739488-6e01-5570-bffa-a4062b553518",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2074ac-52a5-56a5-a058-b1033350a8bd",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c111b1dd-a34d-57e1-ba6d-63d3d839ee45",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f834da3a-3dc3-547e-b45f-455fd5366917",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e1f2be6-79e7-5de6-a54e-39d87d8fdbde",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9e571e0-ae66-5f06-985b-80b5328731ec",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddd50494-432c-5566-96b7-974af0305a9e",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eda1c04-f6c2-5fdf-b285-e5f60647d03a",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b4cf5d5-e87d-5d69-a043-1e52db8bdf38",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01991eed-b6b0-5e70-aa2d-9edaf2eb2561",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52e93801-2563-5e7e-bc66-9b7b18ec088b",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0fcb0215-f064-502a-b10f-e3ee68679ed9",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f553da1-749a-5f01-8f53-e7b975ce5569",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3cab88b-1cda-57d5-8a06-d3c70ec6fe42",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92b855fe-ac83-5b9b-bbc6-87c206e52052",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-servlet-compatible 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63cc1b23-c0ce-55c1-85f6-cfef7fbc38a4",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adf3dc03-c1b4-551d-ba87-c369a5b7e586",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-servlet-compatible 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8da761db-11fd-54ee-bead-fffd2d055121",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5eb68bf3-8542-5e58-9334-9c73263f9fee",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-servlet-compatible 3.5.11-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c44776e-8447-57b1-9a0f-bd7dacede646",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80470689-de87-5ce1-b754-b5b645fab953",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.1 of org.apache.cxf:cxf-servlet-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-servlet-compatible@3.5.11-tuxcare.1"
    }
  ]
}