{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ae98c9de-4634-5b9b-ba27-13e455bfec80",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-spring-boot-starter-jaxws",
      "version": "3.5.11-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:e9caf082-24ac-5386-a836-d098914a4032",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b11708cc-ca05-541e-9cc1-f51e130095c3",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ba57ab1-4002-57d1-a8f6-0e43d69123ed",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45cdcabc-a9ba-5037-a2db-3dd2f9c56d86",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1a13253-64f9-522d-aad6-a6b0b5249ef3",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:299f2ad0-ad99-5238-b418-b35b7bd58e0f",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ee1ab53-a396-5207-a696-10bb0d9082ad",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e064a3d-7fa6-550f-9d49-57cbd86c28de",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8b84d1c-c746-5f63-b127-85c630abc51c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8d4a62b-ee74-5645-8bcf-ed2248af1fa8",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed66f465-0c5d-539e-bc12-14f14d3765df",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40eaff5f-fe1e-5c52-ac0e-4f202e2020be",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f88aa85-a726-5fe2-be1b-684bb77a8b31",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddb1c53a-52cd-565e-b0e4-9d33775617db",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7521d20b-4c1a-5a75-a532-1f50b8b8a4d0",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06d9ad69-5505-516b-966e-93a6a04b3373",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07929c3d-0b63-5994-823c-54166ba9dc88",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc9ac8ae-3b8c-5956-a510-94bef74dcc00",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05a07dae-f505-590b-bac4-de7d8a4602b1",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8f66867-43b9-5e41-9840-21e8d5cb78c9",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e50e7d24-e3f5-591c-82f1-a8a231818d1d",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fecfa84e-a778-58fb-810c-bbea3a6e5d40",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:890514c2-2879-5d38-aff4-6a022364dc95",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f259f94-d3e1-5529-83d8-a83d91ebe4a5",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c223e668-0ce3-5031-b123-3dc4c8fd290c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21846746-a697-530a-a5ea-83959dd2e28d",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxws 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec3fca0-a880-5db7-9bd0-260a896f4b22",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68f5507f-8e0c-5984-942c-514021197b7e",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxws 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e496004-e264-5fb2-9ebd-a3e2300a6070",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb63fed5-2f38-5426-8944-ec3e95e11193",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxws 3.5.11-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5db89b4-487f-5467-b479-8027f2bf1ff2",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7374687-1d36-5a40-82ba-5413d7879707",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.2 of org.apache.cxf:cxf-spring-boot-starter-jaxws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxws@3.5.11-tuxcare.2"
    }
  ]
}