{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ffb5d352-4bcc-58b0-84a2-0dd05c8ffb1e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-dbcp",
      "version": "9.0.75-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6a96aa0d-8650-5afa-98a3-5203f7357705",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe06fb7c-bbac-519a-b80c-ff7f2dd4148f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a189563a-cc47-5d57-99a5-d5533c97204a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac959965-7766-5544-bfa9-58e6845b525d",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:246d7dad-9527-54bb-9014-d89829255422",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23b17b6e-1d9d-591f-814c-dd4417b15b62",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4731ae1-12ac-5b0b-aca4-46793f16cf47",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d711a5-27be-5045-9aef-5ea5c3d6c90f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d3991c2-32bd-50b5-a640-6bdce7303d9f",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:523e0a25-d98e-5b5e-83dc-9cdad2c98e6d",
      "id": "CVE-2023-42794",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42794 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9cf6afce-347e-543e-b718-87deab1941b2",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f0fd156-2c36-52cb-941f-62b39a6ae989",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8fd5d5f6-c2d4-5798-b52c-ea062f6e55f6",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8ed937d-4acf-507c-bfdd-19a4896cb4ec",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:516524da-6722-510a-8df2-46b4917ffafe",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-23672 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17b19c13-eb14-5bf2-9a3d-494c639f28c4",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-24549 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcc0bbca-f5db-521c-9f03-a35e4961c83b",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8869266d-715a-5fc1-93f5-b614b6b5b714",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b64ed51-d744-5ea0-bcd9-b2cff19d6808",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11f32e3d-1f36-5d5d-8868-1478ea6b6d0c",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a36b7790-7c0e-5ecf-b1e5-f6f5d6bf8f2a",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-54677 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:535cf6ae-c931-5c95-87bd-c4ac0b78bfd7",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf406fa2-dbc3-522a-b9e2-bc81a6f33168",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ca7774e-e5de-5b8d-9f1c-37b87c492bf1",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91f6feb6-1c9a-55a4-a91b-46c49b9146e8",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:005c5535-a82c-59f2-aa38-a9bbd19db2b8",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8392c98f-f013-52a7-9050-1d11508e6df4",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02855d39-44eb-5358-97d7-890a32ff1f57",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9827743f-47f0-54ba-af7c-e018c702e63c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b861a3d3-06f5-552b-906d-def8fb937fc8",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56bdaf54-982d-5b87-a05a-53f89ab7dc36",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75aede2a-9552-5749-8561-f065704d6832",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c8a911f-31a8-5ef5-a368-f59824753125",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f91c0b25-4e7e-5141-a1db-4f64b2fa1f5f",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:666a0ff7-ae1d-54a0-9262-3bb07e6b1dc0",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c6e4099-c586-5202-ada2-d4806d98bd0a",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0e19aa5-81a8-5920-b99d-beedda3b3df4",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9229dfb-4e39-5633-a8af-8f33f3802c1e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c01d2e69-6c16-5a9e-b2fb-55e862cffe59",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b67d62c0-b682-5f6b-855b-b2286d216bda",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e1231a-ae6d-5d66-8087-cfce7fe2a55e",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdb9b4ee-6521-5db2-94c2-595f39f56dbd",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2f05841-d374-555f-902c-1dae8f476f11",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e66c4bc3-5429-5031-8795-10fcc3cc7a8c",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5fc58b6-161a-5aa0-a856-96585fc0b18b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.75-tuxcare.4 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.75-tuxcare.4"
    }
  ]
}