{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:5566a2f0-2a24-5a58-a847-f873886fbc63",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-spring-boot-autoconfigure",
      "version": "3.5.11-tuxcare.3",
      "purl": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ec973407-33f7-5e93-b9c4-6e3135c54218",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:662398f9-026d-553c-8b67-7208b76e598e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15911340-5b4f-5582-9fa0-56dc9d68df06",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31efc697-2229-5ed3-8442-a31394d6c97a",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e430f6df-ad21-54b1-b61c-26fd79ba0231",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c53e5b4-2359-5023-9fcf-9186dd945d4b",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61c69bf9-2652-573e-a205-2f2ac84843da",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d6ba831-741d-51b7-9c99-57a3f3a74467",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b825a9-4ad6-585c-8573-3e8b247df0c8",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b0144b-fbe1-5b14-a05b-a7b054fe1751",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f024e880-7f4a-5899-aa29-bd1359809599",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cd91037-b380-5c70-92bc-c3bc9546036e",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc2e4af-831d-5684-9692-ce57055adccd",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:522b480b-e003-5309-82db-1488329aafbc",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd19144a-2e85-50c5-a6d5-37db31869011",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17f2fddb-a0d9-5fce-a126-b780671128bc",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3f36842-b0c8-56b1-92ae-c42d378696ed",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3741ce6-8b26-57a3-86ac-bd6a88f5f37c",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad351de-9f5f-51cd-b8ac-77f53379a118",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f074a992-be2a-51a9-aced-38331da9ce07",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc202694-4981-584b-a26e-0feaaf3a484a",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7b1958e-e885-58d4-8b75-301b2695f434",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f34a1c96-7ab5-55a4-b143-d3d7bd907d8d",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d9a08a-1e5d-5054-911d-ad430ae962ee",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8c6e23d-713e-5d3a-a5ef-fa338af1c538",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:328293a3-7123-54d3-9bfc-d990539577dc",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-spring-boot-autoconfigure 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0737fc2e-f587-5653-b793-5ede39d26783",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8d13da2-b460-582b-8c7d-34b8a90214c8",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-spring-boot-autoconfigure 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:903cafd1-d320-5016-b354-d075eb651972",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44df1f36-5469-518f-ad47-d1f903119889",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-spring-boot-autoconfigure 3.5.11-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c3f067c-e54c-5887-b6f6-d5290194dce1",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4144eb1-43a9-5e23-b89b-e249709dd8f9",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.3 of org.apache.cxf:cxf-spring-boot-autoconfigure."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-autoconfigure@3.5.11-tuxcare.3"
    }
  ]
}