{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3d0d32d6-4f32-5351-af0b-029f90147529",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-dbcp",
      "version": "9.0.75-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f477ff85-781a-567b-9ce5-15d4de744e6a",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e23f779-62ca-5713-a832-357dc858acd6",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fde03b7-56d0-50f9-92b3-a9f38acfcf61",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07641920-b779-5f44-9dd9-6d88b6aba4dc",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e72931a5-dcb3-55d7-92c1-58ddaef930bd",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bff704fd-1460-50ea-894a-821ee30f4135",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c11542f9-5dfe-5316-85f8-79081663e5a4",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66783b77-7cbc-5c30-b1a8-d26342e21ae5",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f14d914a-c93d-5c5a-a7eb-927fa02ad3b3",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10ff0357-85a3-52ec-955b-25e2356d2489",
      "id": "CVE-2023-42794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42794 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab80b3c4-d328-5436-b34d-3da527d8aaa7",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d92b89-5f5c-5111-a446-724447c1200b",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b27e80db-f08d-5bc5-a25a-0d1aaac5ca51",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:360654bf-93ce-53ca-a0e1-eee975818799",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3862a438-c6d1-507a-b504-0e43b167cec7",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05748e18-75f1-5bcc-bc85-fd1a3ee99cc8",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24549 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f6ff001-6c1b-555d-8fb2-37a50cb5d4b6",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073d0831-1ef6-50ae-9fa3-0d522df15c16",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a12afd77-02e9-51b8-843a-88e5b14f755e",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:be7516cb-1d4d-5e23-a7d1-cde5ffdbeaa4",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d4c2b00-d0a1-5a2c-a45e-323acb805fd9",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-54677 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6184ab8-cebb-5ee5-9170-f1fc33ddb8b5",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac2e3955-e1f9-5c64-b210-45550676a1ee",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c05a9c6-4f26-5e89-8be3-3f136750efc9",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:528f53ff-5f44-577d-b9b2-0e21e757ca61",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:965178c1-f8ce-5263-996f-946c3ce19927",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad3ea9ae-177b-54c7-abfd-9754203e1c8b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4363ec11-cc91-5be7-a673-bf361b46d033",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:870bb31c-182f-55a6-b49e-233ded4f8059",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c28927-7f4e-53a2-a81d-d6110dfed157",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852b59bd-8a10-5706-9cea-87ce20aa8401",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f01123a-5e23-5bf2-814e-38bc90c17454",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:215da14b-3300-5d41-a3ae-124e6b4e64eb",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53506 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d2d5685-87c1-512a-8848-2dbd63951420",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55668 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26947df0-e2d7-59aa-b089-6b9abd2bfdbb",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5557394-f8bf-59b7-a2db-5f37460a6b78",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55754 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e63301c-671d-5a55-9127-5086cadf185b",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-61795 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efa5113f-3e31-5a82-8a00-b9277d4465bb",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b52679-29ab-5a3c-b4bf-8ff593933c05",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dbed364-bc8a-5347-ae10-dc8f56162e67",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad3725ca-20e0-5782-b796-42346ea0a237",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa187e7-aea3-53b6-bd1d-9c8139e3073c",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f47308-7fa5-5ddd-868e-e30cb437f65b",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7ffe885-3105-5d64-b20e-e1b8d4624f63",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d6caff2-6fe6-5b9c-84ff-6e10e9e97f94",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.75-tuxcare.1 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.1"
    }
  ]
}