{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ba495a62-f338-5e93-8a1d-cc283567c994",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-dbcp",
      "version": "9.0.46-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a78303a4-ef63-5bc6-ae56-59962bdc6529",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:49168bd3-efee-54d1-ab41-af1c93ce51c2",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:426bff26-3df7-5bde-8ced-2913ac2419b9",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9052850a-a68f-5e07-9ec6-2dbc03fff1ed",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:307f37ef-b31d-5d10-b1e5-a020842cdb13",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5574ef0-f908-5391-ab9d-049fb6c4212e",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b7886ae-3ceb-5bf7-8c92-783c7ae63b5c",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc4e954b-84ea-5b90-b997-ee318fc6b340",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cf51d72-6d09-5faa-a3cb-5379060b7c07",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f6e12f1-d2f6-5e9f-bb51-0483c4ed52d8",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ce0bab-f505-5b80-942c-bd43c8e20b02",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3611ade6-de34-5d0d-8953-2f6d4fc5364a",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a5b241f-36f1-5969-b431-d70efb5f8815",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2379f3a8-55f1-5c82-a2e2-44b61288cb6a",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07c44705-58f2-5f3a-8e44-257aece6b79b",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2558a2a-3a52-5d2d-9596-9cdbf57fc1f7",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:867baaef-bfd8-52b2-a0b4-e21706f6ab57",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2576be62-2b38-5678-bbaa-262b7ac64519",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e69d4fb3-91ff-57d1-bc2a-110dbfe296c6",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30436543-3b98-5278-b4a5-63550f8e21d1",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7ce8c6c-0cf5-595c-8440-749a6d37a733",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e93362f-9623-5c71-9a98-8df761dfd6de",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c16f126-4dc3-5b1f-9df2-1955eff7ea35",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35d48bfc-5e97-5e0f-86a4-9e06d6d334c1",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a91aa111-f09c-552f-825b-bcc4fe2cba08",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8310f69-5ebf-59c1-b69a-a778cf13f6b2",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6d30887-c4a7-5ded-a76d-22696b9a16ac",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a71aa09-0d4b-5212-9536-ef3edf05b3a3",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c10b166a-78e3-5206-bfe3-ea5713bd72d5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:657c4197-f8d9-5280-88be-002ed658df8b",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:060ef6b3-2d39-552f-bd1b-9e34b3776110",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2e38feb-b3aa-5689-8149-686eb3655e78",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c74b8e9-538b-5ef7-b21e-b002e4e5e229",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57bffc4e-8a63-5309-bda1-629579a6412d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97dce569-07e8-5abe-8dfb-3cb68e652c8d",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da4bb862-9ebd-5edf-b745-9e84037bac93",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a8197bb-7f15-5bc0-9f6e-08e2b5378039",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dc1162a-5d96-5886-8305-1d56685deba2",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e78c4b7-66c1-5a93-877d-3e182d36fe03",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d0fe7b-33a5-5cb1-a114-1045ef9d8ba5",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d63ff28a-af90-53b0-a6cd-e899368b05e5",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6694c4b5-5123-590f-84ff-295d6731c160",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1da0d7cc-c70f-5e46-b943-a9a33df43c3e",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e31db9c9-4732-51f1-851d-5696765bb2a3",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bbb884b-8bbe-5fe8-9edc-77da2145b11f",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9654d37a-8fcd-5815-8668-1ba11afa81c3",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12736547-2a5e-54bd-8dd6-a940056caf5a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd05adb2-975a-5bc1-b9d2-cd11e166dbc3",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9343cd75-0a02-550b-9a55-fac72f5c209a",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38ddeaae-e6cb-5994-b621-845914d4dca0",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35c7b966-8695-5d2d-ba18-b143440d7fed",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.46-tuxcare.1"
    }
  ]
}