{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6ba6fd0b-7142-53bf-9f1d-399a6584286f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina-ha",
      "version": "9.0.87-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:31ded4fd-1f4c-55ce-ad0a-20c66fc90b2d",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8049cf24-9556-58f3-bd08-30d5aa8afefc",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb5b4728-d948-5234-8bcd-a6608e87e5e8",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af28b420-b462-5796-80cc-da86c95b2520",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a239585-c114-58e1-abe8-d32f4ab7a5c2",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf3d156-69b9-51fc-858d-a0a898215ebf",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dcf5931-0058-59b5-abeb-de89745b86c2",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d01fc66-b02e-5068-9a13-fc04c1f38741",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73304ca4-c6d7-52af-83e3-d7a581ad27da",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2a03809-2148-5c52-af2b-2913fddeebaa",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a1ef462-284c-5f54-9d6f-8460126c30b4",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d57bbe78-b7a1-5b9f-8854-92a12c162ccc",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f397b6ca-13a6-595b-9fe3-574cb61c2aa8",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d6451d7-fb00-5ad2-a77c-f07c30ff404b",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d8e3c0e-786f-5b92-b866-d2949a848ecd",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8328ee4b-09fc-5d5c-84c0-8ec6563b0fec",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6351360-22f2-5ef3-a996-5ab1512db3e1",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ca24c39-dc0f-579b-8bc5-0669a1c11d42",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b9fb0b0-550d-5685-8138-07d4565233b0",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81e4ac67-0237-57a5-84ca-cad5422354f8",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:266b5e18-f7cf-5a2e-bf6f-4e26fa419689",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f84177-53da-540a-ac53-65555f629bb5",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13f2d477-bbff-5eb8-94ff-6cd03bfef2a3",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b43410-9599-528e-8f53-ec92dd15e067",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:226f22f2-ae81-5488-9357-b53c0fda7c2f",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24fabf0c-33b2-5cb4-875a-ff7a7c58255f",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37050c3f-6368-5652-a108-e5e8e620e827",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4385fcee-7cdc-5192-a0c8-27414ce9a3b1",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6f80a08-1c82-5e10-8809-d32decf060c9",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24bc5f2b-9654-55ff-a226-145a14bd1e00",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7258ed5-032c-5dc2-ab7f-b9c6779f76b1",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64f06255-d00d-5681-81c7-ed0f97838469",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2301df5-4550-50f9-87a8-102985a18312",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e77a0cf-11e0-587c-acfe-55869b51825d",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f793d21-aeca-5c38-9aa0-3605931deb2b",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a2c6c8f-85ac-5c67-8c64-74fc8979b381",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8529a730-1a10-5be3-a70e-4a0b63eb79bb",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcd216c2-9e12-5941-acbd-06452037340e",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:277d513e-4ebf-592f-8c20-b9fa6f657a91",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b318314-09f4-5509-8da0-d318e62f2fa8",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef208036-0b6f-538a-86fa-1d096f0f1ba1",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-catalina-ha."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina-ha@9.0.87-tuxcare.2"
    }
  ]
}