{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a5aa6d89-fce2-50f4-b34a-447af48f389b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-tools",
      "version": "3.5.9-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:295b12f2-cb57-5502-85be-e188f69fe724",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b15ed7-a712-5c1c-a035-e3f32c2fc900",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf724fe1-c328-5ef0-81f4-c080539ab29d",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8951353-975a-5aa7-a522-2400672a0782",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bba3c524-13a3-57e2-9554-ac7be7ecca16",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8894d59c-5071-5b4a-b74f-f74911edd665",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d385432-4f90-5edc-9921-c746ea8ad647",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de317a29-0a31-5dd6-a9a3-06e401f8a537",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:790bb85a-4bff-5337-bbe7-cf8c4dd3e2e0",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c134446d-16ee-52a9-b0d2-02b966640191",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d9f85a4-2516-5cca-b75c-0941e8750718",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16778e45-72f1-5e4c-b57d-8cda8b4f9f8f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48e3f17c-0f0e-514f-849d-acd45d2c0390",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f52c27f9-4830-59be-bee4-5ddc3c1f40a2",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1878efa2-bf22-54fe-83e8-13bd9cbccf9f",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1a06b07-6e48-5b9f-a105-4def13ee9392",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb350a2e-6f00-5f14-9391-6d8317a76309",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-tools 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71e82b9a-51cd-5507-b978-9cadf53c8735",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d8d9f3d-8263-59e7-837a-29056ac9c7d0",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf5b7621-0b91-5e8f-aabd-6bde5a5f170f",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8e0b9e4-4749-5689-9149-47c43478f281",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63f66e49-fe9c-583f-8ae4-2e2f83675082",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:292e2abe-c956-509d-a983-9967c6e9c671",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b181536-1201-5dfd-b9ee-8f890014d3ec",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be006c88-fe35-57e4-bdd4-63917f338b77",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:023bda5d-8230-5607-9dd4-943689494d45",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-tools 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f3e26c6-5039-5c1c-b4b1-9898da8c460b",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de032a1f-f3eb-53c0-8797-d3f0b3315428",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30fbbbcb-41e9-575f-afd2-b9ed774b4390",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0285f50c-2e3a-50ad-99bf-bb44f2acafeb",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-tools 3.5.9-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83b62bb1-756f-58b5-9ab3-b8fa576d3f00",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e687e9ff-c188-5cdd-8167-3ae41683cd9d",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c93cb05-c45f-5fbc-a900-9a0e924733d6",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:455ff90c-795f-518a-993a-cd58f11b42b1",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.4 of org.apache.cxf:cxf-tools."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-tools@3.5.9-tuxcare.4"
    }
  ]
}