{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ef78d53f-e184-594d-b13c-3903793fd91e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-tools",
      "version": "3.5.11-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:da9f8354-a210-5942-8f36-4ddfefd0b4ee",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce8ffbb1-e807-52db-b0b2-980e37faa4bd",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97eb568d-285e-5810-9d91-3e61430859cc",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89bf9b0f-bd59-5645-b3e3-b68fa50b123d",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5b11462-aa47-5a67-9d13-63854061cc24",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e5e1eaa-903c-5242-80d7-147d6b90cccf",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:264ce95a-b153-56de-83c7-35514604fd2a",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eba5676f-2f93-575f-9a54-a4911cd00b95",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a92c6a-59a5-5f0b-a05a-187a91ac46d9",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfbe1c75-567d-5565-8ab0-176f85e537c9",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5adbd353-ec9a-5be3-919a-2ead975e2b61",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b62dcc80-9c2d-507c-b831-59606b7cb056",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a040006-aa43-5c9d-a9f4-9c7a30b2116c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36cd64a5-b7ea-5baf-a3ed-7dd9188ca52f",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30b536cb-032d-5a56-87a6-1a23c5c4a581",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c734cb8d-e536-5ea6-a8de-c252170d236e",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5ad0bd9-7a45-51d5-9b7c-93213b783e59",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97ba18eb-ca1f-553c-96df-59ddd81b0f1e",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:359e279f-7d99-5e34-aede-9b8bc02fdcde",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05077284-d733-55d4-8a3e-739bee531787",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4d7f72-c6b4-5ae0-8784-a021f2032bc5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8735653d-97bd-5471-9d0e-a04b97119307",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7337cbe-1a57-562f-b375-efd9e4e7a6b8",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86f87cf-51c4-51b8-ae30-d711de0b9918",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd54049-e56c-5ad4-8fc8-04e7eb397796",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:affc7abc-7e9a-5f9f-a4e8-84b079d490fa",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-tools 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86632621-70ee-5018-817b-7d8d505d94e1",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:318b28db-d554-5aa4-a3da-73fceab49a44",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-tools 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e99bd83-d624-5fd4-b02e-259cc6106945",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7905890-df74-5c49-9a89-514b41e7023a",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-tools 3.5.11-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9238a56c-691f-5e1d-86c6-ebe09418ce28",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86991047-86e4-5b01-b2a7-6e42a1f4905c",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.5 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.11-tuxcare.5"
    }
  ]
}