{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3f3041e2-dffe-5079-81ea-b8273cb4e448",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-tools-java2ws",
      "version": "3.5.9-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:72e62ee4-8b5f-5807-83bb-b77655d05f25",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac39fc87-c2ad-5356-8d95-5a1026dd11a5",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03ff4c43-b3c0-5903-b9f3-6db4d2330818",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1e854e1-86ec-5e1a-9620-7609ec3aed4b",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9754a7f1-8503-50ab-8c76-ccc77d4d556e",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:066280e2-937f-5098-8b9e-79ad2badff2e",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8820dbf4-bf6a-5851-b2b1-39b507323b47",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5469cb5-7a31-5f14-92e9-fab53069eae4",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb321e7-7370-51d7-8008-7211fb05277a",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f57a45e-6859-5e0e-9fda-dfdcaec95cdb",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:474fe65a-1466-5781-9183-66ed2b13208c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edade6bc-f432-53eb-8dfa-9ccfcdec2a5c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7510b5b2-cdd2-503e-8274-ea54365e953b",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fab0c68e-f040-5def-a17b-6d505d683ad0",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:718b1ed5-6fe0-58b5-ad87-38cecbb17e95",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:846b712d-b2f6-5ecb-b054-da9eedfb6790",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5a237e2-b143-5fd5-b0af-f02ed77746e1",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-tools-java2ws 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35e75d64-b15e-52b1-975e-37381c7e00b0",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5054e95-1655-552b-98f9-62d137899c18",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ee2ff53-6781-5adb-b934-5205cbbdc559",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56136fe4-c5b4-5aae-832f-cd162a424ea8",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae4f7483-064d-549b-9871-e6bd2510174c",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abab408c-277a-576c-a670-32024672572e",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a4b10ab-3787-5bed-ab21-b0b4b0da6b96",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecaab91c-a4fa-5cd0-a9e2-7ef85ae063f2",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85b8e069-21dc-530d-a49f-87791ace610b",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-tools-java2ws 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61995f83-756e-5eb9-9a6a-daa38b2e3a19",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:306608da-8023-5a74-b0d9-501a058096fb",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:180b0ad0-2d61-5a85-87c9-0120be6d2b0e",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852bccd2-7a8a-54da-84b7-d52a57112e0b",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-tools-java2ws 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57dc54a6-ea33-5faa-b855-fadc6821f918",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d401aa33-3020-5e1e-853d-0096a05d45ed",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27e3d322-8a35-5075-83f7-ae299855e553",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0886ef2-9b98-56f8-a504-0d479fe44446",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools-java2ws."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-tools-java2ws@3.5.9-tuxcare.4"
    }
  ]
}