{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c6b6cbd9-1436-5720-a74c-7af3d79c7ee0",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-wsdl-validator-plugin",
      "version": "3.5.9-tuxcare.2",
      "purl": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:066d3c50-f62e-57f0-9d5e-57d1f8d21a90",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a416c07c-b7af-5e7e-8d33-7862cc2ee179",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d5c73bb-eb9b-5204-852e-c5bc71426dbe",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88437ac2-7def-590c-aca7-d351a6e62c7c",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ae1e7ac-71eb-5be6-b287-35fff3099ed0",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dde44d6c-33bd-53f7-804e-0b593b5fd074",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1d65a1d-8cb3-5b2b-97fe-6375f09d8d31",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d771e44-00e8-5b8e-b6cf-2e2cd638f5aa",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c8da7c8-5841-5790-925c-acdf22bc5c98",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa3e9254-024e-54d6-8565-b9fc49c29700",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f2d3004-aace-519a-915b-ffab94434fbc",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f42c0ba7-92f8-52b9-846a-cd4116223b98",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f73812c4-65de-59d8-b99f-2dd2fc382091",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef1c5b13-4af4-5c2b-9aae-7f6b90e41f56",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d441f703-ea9a-55cb-8a3a-fe50f64dfc79",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4982e735-3395-561f-8b0f-1e2c1fe43c8b",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f895069-700a-5e4a-80b1-7a47c796c231",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-wsdl-validator-plugin 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba086f63-de6b-5600-aa63-3ff66b0a3f05",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35f81ee9-d09e-50e4-949c-61008108cd58",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d65e82f-7758-5bbd-9173-169daafe8137",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c3c1e0f-e420-5407-8a02-7916d46d1b5a",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9064365c-2c05-5427-a4c4-4c478c4f1a24",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4f485ad-7d67-58a0-9fd6-0e81d45c340d",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50a3a1dd-4b32-5fbc-8eff-e5631a69f673",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f53663e4-339a-59df-9308-d6fcce4e8502",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c1eccc-aefe-5a59-a981-633686dd2d7b",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-wsdl-validator-plugin 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26dd052c-e79e-5f02-95a4-229cc6b04fe4",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82e8a967-bdb0-5807-ba7d-bb4c967e473a",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48c2367b-1141-521a-99a8-edb64161d418",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f23dfbd-a925-5c13-8026-f34541d80f6c",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-wsdl-validator-plugin 3.5.9-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0246e821-efda-5621-9488-d96317e7d339",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c76d45-66bf-53f6-afca-19fbdfc4ec5b",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ce7fa9-5824-5cc9-9b60-10a9494dfc4a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48795 affects version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28ec0341-4510-5d77-b941-0e91cabcb230",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.2 of org.apache.cxf:cxf-wsdl-validator-plugin."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-wsdl-validator-plugin@3.5.9-tuxcare.2"
    }
  ]
}