{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ab3aeaf0-bd8d-577d-b982-5fbd0cf426e7",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-jasper",
      "version": "9.0.87-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c2e7085f-2194-563e-94eb-eb95f10394ea",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c118c78e-dbd9-51b4-9c62-61bfeb056e1c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:551cb595-17bd-5681-abf6-366dc07a27a6",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3307a1c5-8f66-5d90-a63f-477d7f1e0d76",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4f1b747-2411-5365-aa0d-503798e3079d",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4df26353-1302-5dfc-babc-1e80136e1b23",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a13e819-1513-51a4-87a9-3c3adaf3429b",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48b2b2c-bc46-5c5f-bffc-9cba1c1edaae",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef1f204-7c31-5bae-acdc-3cc1e166bdb2",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52131822-e08c-59aa-8cf0-63985d2f4b8d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc02a0e-7e3d-56bf-b918-b4ee67ce0479",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9167e4e9-624a-58f5-b2d1-16e66d2fdb86",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e056272-a84b-57f1-8055-ad6c57d086fc",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be2fcdbd-3880-543b-b37e-6f9aced1d18d",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2533d8a2-429a-596c-864d-f7b1b1744e46",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5adb2a9e-0902-5970-951d-14c052c41883",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c051826f-9fc7-54f1-a149-511d8a985910",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18c780f7-172d-5761-942d-b629f089dc17",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3d94b1a-f629-5689-9a4b-4841f0c13059",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ddaf60e1-33a3-5a1a-948e-b779759a32d8",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac1aad49-a9f1-54aa-ad06-136c892ba25e",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf9276af-81e0-5c22-8454-ea036f400daa",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a51fc0cd-59ed-5306-88d3-c7b23498a0ae",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:417f8c2a-4647-59f3-9063-a11155d59a2f",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1af976bc-1c52-5664-8b63-dd88d6c1f953",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:253a8d28-254b-54ec-b4a1-e8c61d7638c8",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c3d3f4-aabc-52a7-80c9-edbe4be309ea",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46316115-385b-5743-b179-b31c84ab3fab",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062003ae-e9c7-5a5a-89c2-c08fceee41ca",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73ef2919-0666-55bf-aff4-de64f72c1a6f",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ff19b56-d6a3-5e39-b8a8-87f537614baf",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d894193f-eac4-5009-b7cb-a4bf44afbbf2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:789b9499-bba7-5bd0-8752-59922309ccb9",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4ae37a1-b452-5658-9d7a-80abdec5f0c8",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a82d7235-152c-56a0-a3b8-84d5ed5e8ce9",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fcbeabe-8c37-55e0-ab86-4effbd8f8006",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef3c053-061e-5494-9bcd-365f8bde65c6",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca6479ab-afde-56b3-93b0-4db8366b5d20",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc2071d0-840b-5a91-a8cd-bf6d2835a7c7",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9329885-e18b-5d7f-839f-db2ad36657bb",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0a28e28-c11b-54ff-87cb-d79cbcdf72aa",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.2 of org.apache.tomcat.embed:tomcat-embed-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-jasper@9.0.87-tuxcare.2"
    }
  ]
}