{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:12a59202-3d53-5762-881f-b6a60638c53d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-catalina",
      "version": "9.0.90-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:65a70fe9-5607-5f5b-837b-4d535ea88289",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cee3d741-8066-56ee-907f-66a02be6e357",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ff444a0-3208-512c-8606-d488f4789330",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b7857e2-57f3-5ee3-b2c0-d70f79d1a64f",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7f6bb58-f4bb-5034-a8bb-57c8d610504a",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18b51e4c-57d5-5277-8264-9de765e9b061",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29279c37-3c69-5af1-9129-56efc848132c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaea41ba-a77a-51ca-90d7-ebb94c94e0c9",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:795d02a7-b33c-525d-8cac-78afd4013188",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:444a60d9-3e60-52bf-9e5d-8a985a150746",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c15af066-d50f-5287-b53b-3435aa0fbee0",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8aa61c0-0884-52b1-b88b-4b6b1df9eff9",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:758353ba-212e-53fd-a0ac-0a5021876e67",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2072d8d-ae49-52a4-ad29-9b528e0ad7b3",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1763ad5-0813-5710-86e3-7e27e1983cff",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4017048-00fa-570d-b38e-788bdbee5834",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c76dfed-37fb-5000-9204-2b8efd29ebba",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eedc0e61-3fe6-52ea-a967-2a0fef958b5a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:adec6238-c4e0-55e8-9f95-24e24d9ad9f8",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:370eb364-7e8a-521d-836b-1a27f6008eea",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd75a585-b445-5073-a813-b4b173966c59",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75196765-b974-538d-8c2f-642d3d8ed91b",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf325527-86ac-56c1-bab3-9d438b7db983",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a826a89-c9e7-51ce-9f79-e7cc8f501ece",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcba2757-26ad-51d6-9289-b905d86c9bc3",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73de3252-bc8b-5904-a222-d50f8cadec91",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4cd4cf7-d470-54e2-a6d3-d89408eb4280",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e251437d-223e-5eb9-bce9-f5ebb40f9453",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a8e3163-6853-5875-8dd5-b7611691d0c6",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13df4f51-a6fd-5c4f-955e-a519664b5922",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9065373-802b-56f9-be53-15f8cbdc1853",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aaa1f61-7afb-59f2-b530-6d74aa4cbecf",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7e776af-58a4-5d9d-99fd-7699280e07bb",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:987faa8f-3ab5-5f50-9945-e573591b43c5",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54c4eea9-6abf-527e-9664-f68d9349e767",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f17ba7e9-c807-53d9-bd4a-eaaf784a1ca8",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a3f41d4-0484-59e4-adc4-405d1c8cbdb5",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5aad244e-cca8-5e38-9f3a-21a8020e2b0d",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c720c750-8487-5356-88b4-ca3bed54029f",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-catalina."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-catalina@9.0.90-tuxcare.2"
    }
  ]
}