{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:449aa7c2-62a5-5746-b8ee-54f7ec15bf0f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina-ha",
      "version": "9.0.100-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:60464fc8-fc1f-5e73-b1d0-e2250074a581",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8de8e9b3-615a-5fb9-8b7d-e9735b7b0ee4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6c88d6ee-0c59-566a-96f3-d6e60960a50a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da372d08-0828-59d2-b0c2-3da4ebb2f711",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad4ecc4-5103-57f5-ad88-d79c77a46cc2",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27129634-6710-585d-a3d8-a2bb99905214",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12775c0d-1fca-5660-91a5-22ba0f8659df",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81c86b62-dbab-5b1e-bd7d-dc285fd1598a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc3c8426-08bd-58c2-b9db-78d53b6f2cd4",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:915bf26d-1659-58be-a59e-252eaa77e93b",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a747e4f0-d412-5e37-91e7-d92e3fcb3433",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4864fd4f-71c0-52e0-8a09-bc7b1f4d2b7c",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3b58cb8-2cf5-5c3e-8c37-f185b8f289b4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41b67e27-0802-562d-a0bc-fb940c176d7e",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0036733-0777-5a9c-8396-f09b7ce89055",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8366d308-38ec-5aea-b652-6db4d863f990",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3cdd77a-5350-5a69-8266-a929ee21898f",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c8737cf-9bae-5b6b-84a5-f5d07ccdcc74",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d40eefd-0c00-5e2c-b9ab-75b93405ae5d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ece52a44-ab11-55cf-bd88-5eb2d225c9d0",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:886c61f0-a2a0-58ff-a9a9-9a5b60a793b1",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b40d5357-8e4b-5023-bbc4-348a4fa9266b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94acca31-5824-5a39-bf98-f86b238d1066",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:335dab09-5da4-5440-9b8f-f53ed2063b5f",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2827bbf-38a9-53ef-9e6f-c90e38e541f7",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9cb7e77-dd4a-5d7d-a66b-8d254fef1d93",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b13bbdfe-bfa3-5c5d-9887-d59d27844095",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea697d2f-658a-59d2-864c-2c53e1903399",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:192eb9ab-9782-5914-8eb5-9f80200a8666",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cc7cec9-9025-59d1-90ca-70c8ab438ed7",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11237820-ec4e-5ec0-a9a1-ad089e110c40",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a68b214-a65f-5b9d-a1b0-08d5989b173b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfb4686-d7ab-5e8f-b076-da38fe448e58",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35826b7d-e8c8-5951-9643-69ef26a82043",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76b9b8b0-21fe-5249-9696-038822e375e4",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83c30281-921a-5537-bac7-1c0f56f66a04",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.100-tuxcare.4"
    }
  ]
}