{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f5d27cdf-12db-52e7-8b7b-638380ef272a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf",
      "version": "3.5.11-tuxcare.4",
      "purl": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:06c7584c-50cf-515a-a48b-8a1b7939d4bb",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3837ce2-501d-5524-9a85-43648cf7260e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4d7b849-6fed-5d7c-98a3-0b50d4c1d4c2",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51e4d811-62b9-5f18-a35d-4613e44fc715",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50a969e6-c624-5065-8613-6a779c43bbf5",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85a32083-3805-54df-a537-c5010e871311",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5902889f-ed8a-5278-9590-2f147709024b",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18520a3-d181-5dfa-9328-1121c8fdb252",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1761fcf0-ff7f-5f07-aa9f-885772413869",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b147b80b-b9d8-56c9-9cfe-5cce8064baf2",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c0eb420-e804-54aa-aa72-b7965e2ba173",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b5e6d93-6a9a-5703-915e-27d8d3bc082e",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c51825-c6e5-5b30-8bf9-7cac305f5c3c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f25d9c5-d833-53b5-9f3b-cd31318fef80",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fee6f52f-8482-5784-a9a5-8b73911aa8cf",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bebc073c-347d-5ce8-9ea0-88f0d2d9c4f8",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5935c6be-f36a-57ef-b93b-0427d991109c",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18de474d-036b-5d14-bb7b-06b699423dc0",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:77acd0b9-21ed-58cc-8e37-7392128070ad",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ba6fb5b4-7daa-5b64-84e5-22968e376321",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e523cc4-e332-5bf6-8109-6bdb906a3af5",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f12cd27a-c0ad-5303-a52e-8bca1b6133c5",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3634671-2527-502c-b6e2-68c506ebbbe1",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2788ad5c-e87c-50fc-9570-33edca4eadf3",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1215d61d-e4e0-5697-a91a-ba39a65c06e4",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5deb1d2-c960-56c7-8865-396948b9a4a6",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70493dd4-146a-5359-9990-f16cd3333241",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e7bf362-2e9d-5bec-a153-78e7681af906",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bc5c5e1-d5f7-5b20-bf81-5d53c2236f5a",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efcced47-7b24-54b2-a2d4-845f7c389cbd",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf 3.5.11-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:967512b1-a755-5d57-8706-0230e2c600f3",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ee6af32-543b-5a84-af17-11ceefa5107a",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.4 of org.apache.cxf:cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf@3.5.11-tuxcare.4"
    }
  ]
}