{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d6f5a881-a117-535f-99ea-3072c7804864",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina-ha",
      "version": "8.5.100-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3b49029e-9fb8-5b2f-a7f5-1c09f82edd1f",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c793a3bf-c6fb-5593-aceb-cc8ba313264d",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:209a3955-caec-5f16-b284-ff208c094012",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7356a2e2-d8d0-52a9-86d6-4a45a668f554",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d7531a-4cf5-545b-8748-cec4f422d510",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:948c231d-3465-5907-9e91-b9dcea273bff",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3a54168-1302-54d4-b873-fa0952d6e500",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6816 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:680ccfb8-e3ea-5301-a253-7f53327e341f",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6817 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db9e138b-c955-5194-8559-d1ad4b82a2f3",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b60ee8c-f492-5519-a69b-5350805deddc",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8747 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:402f62dc-29ea-540d-ae40-c34183337d1b",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f8eca88-3e5d-56ea-bdaa-466e16f8a1a8",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f019bd06-fb8f-5554-83df-8c9ad305165c",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b25db574-d0ed-5a74-b308-3995ce90554f",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5650 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4be615bc-7eff-5356-a2e1-5f5f785de81e",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd5f3fcc-ad60-59e1-8aa2-9455e8e763a0",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b69f868-3667-5d92-b0d5-be2201174db3",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9492e1c4-cc18-59d9-8d23-8f9bc3f1e5bc",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7675 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c34ea0e-4123-5a9e-8bff-d976e05e92a3",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce341275-4279-55a6-86f2-4a30dc460893",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1305 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b26d99-f87a-5036-adb9-acb60771ec30",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1336 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aad465b-0934-5846-9df4-8ca8723d1cee",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8014 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d82cee9-8ad9-5d85-adaf-066cd833fe52",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36697373-2100-5e15-a17f-7757fbf59845",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f31548a9-faa4-595e-9615-a22b5264b8a6",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b4226a5-38e5-5090-816b-821b586c9d69",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d00a190-86f9-54f4-bceb-5d3aaccd12d3",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.tomcat:tomcat-catalina-ha 8.5.100-tuxcare.4."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62c1a241-ffb2-5964-b097-c674c2517726",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51dc34e4-8155-5c35-a74d-c6453d486d8c",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7adb11ae-a12c-5e29-9dc2-d6c38fdc9079",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47fd30c5-3923-560b-bed5-70cf5e4eb1a8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31e1c723-0632-54c2-b045-ff5a3b655dc7",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd4b3ef3-c1de-51e0-9579-e65e5e10b95d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a27fc32f-5f62-57aa-afec-c9cad1f2e6df",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3d1317-11e6-56fb-a092-9891449526b4",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6abd2b0-167a-59f8-9755-81bbfd01aa62",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d210a153-8c21-5570-bc3c-b74e91d140d0",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b9cf60b-fe9a-5437-b293-e1445545c137",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbde8e4a-f394-5e5c-8314-dddaf9415366",
      "id": "CVE-2024-52317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52317 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f045e9c9-a5a8-5424-80c4-8017805d8b5b",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da2729d5-9c5f-5cec-a3f8-faa619f25030",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:141f3180-4d27-544d-a8d5-f16f56403d52",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bf90648-46f2-5e2c-9c8d-bbfca51bfd24",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19e3d6c3-4540-5f13-b948-626cfd55c037",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15add6a6-3c1c-5d5b-880f-0b1f1e60fafa",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6502209-4965-5edb-b158-0ae933623116",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03b8b8dc-4fd3-5812-8a64-22fd9d57bfe7",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36f8b834-05dd-52a0-9252-cf8fd313cef1",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69c5e765-e3dc-52b0-91f4-20aa636f47b5",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb0325c-bc97-5c84-885a-58fe1325073d",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53506 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31087670-9fa2-501c-9b44-f0f0043a2314",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f94bde08-f397-5e94-9c7d-ec1dfaa2abef",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad49cfd6-7f38-5f69-a43f-60d0e63c9286",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55754 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b4a94c5-6551-55b4-ac42-720882158143",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-61795 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37fd74a5-83eb-53ee-b182-8e3afb467cb1",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36fbd0d3-640d-504d-b394-24e8cfeccb98",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e7339ba-0151-567b-bb5d-9809b9f00e3d",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc24f863-fbe6-53c8-bc77-f57a00fb391a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70618c58-0be5-5f05-9bb1-0591a0563c00",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6e57b6c-1eca-56e2-92a9-5c88999714c2",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 8.5.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@8.5.100-tuxcare.4"
    }
  ]
}