{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f6e633ae-d29e-597f-a9c8-fb8844c60152",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-spring-boot-starter-jaxrs",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:7c7156cf-40d4-5a9a-b1a1-ccff6d5904e9",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a74486aa-fdd6-58c2-bf96-aa91fec3a008",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51067da2-17b2-5d1b-881c-d40074935e0c",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79d70e95-5b37-5a1f-a089-0a2021d74e98",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c75fc45-6126-5e24-984c-ac0c6ce6a471",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f26fc084-9061-5d88-b87c-643810f2c197",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c8977c0-cad2-5a93-af9d-6719148abe4c",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e792941-c0c5-59c8-a09c-856d6c3ecd46",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4982bd30-b599-58ee-a7eb-417b31cfb383",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7c9ba96-c0ac-5836-b301-c336a8575624",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3f40f3e-55a5-50f0-907e-cc42314842b6",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1963c3a3-d8cb-596f-a7d2-de5c4e3d8c95",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f286c3a4-cae9-5417-ad19-1e610ad554f4",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:156098fb-3932-5232-8dcc-dbbb2e35dd29",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a83fb3b-be92-56be-8a0e-5fd52f2fa7c9",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d7a144c-d64c-59ad-bdbf-78d4308bf1a0",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b49fa450-5146-58cd-af5c-72522298229f",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:305f13ba-04ca-586c-add2-4ae59af7d24b",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38bfd611-cfdf-5793-9b2c-225e7e39cd75",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba90bf77-6708-5186-a353-5856147f19af",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eecd02b-66e5-5f4c-aa7a-336db6e5a4e4",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:657375d8-ad11-5cf3-bbf3-5ae4e911883a",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04f39ebf-5bef-5a55-9ee2-55180ce0b587",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3ce18f0-aa5e-5e49-bc25-0df6b2049b6a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b151ef7e-2214-5601-b207-aa4336646baa",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5b76161-e64b-5f5a-8c71-7bee9820b651",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxrs 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64dd0e89-433e-5a0d-ab07-107d3dda42e7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43fe4156-c24d-526b-8b58-128657c8467e",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxrs 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c20e456-e32a-5c6e-854e-31aca7914724",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c434bc18-98d5-5717-94fb-63e2d84acd56",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxrs 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b39e5a0-922c-5261-b949-022b678ee2a4",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19815a5a-d971-507b-bdb4-e9c1c31fc6df",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.11-tuxcare.4"
    }
  ]
}