{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:277bfa9b-a468-5a76-9a80-3143bd685e3a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-dbcp",
      "version": "9.0.90-tuxcare.6",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:78b490f4-fc17-516f-b38a-d54a1f6adab2",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c93f3f-508f-5856-b5bc-5462a017ef34",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:342effa3-5ad9-5164-92a9-df93e99af3f0",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907ff4af-8f4f-55a7-8a3f-e48902dc2e21",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7bcba72-aecb-51f1-94a4-5be382bead5a",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29e12d57-8b3a-550d-82a3-66990ef75894",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:176e1119-3575-5e78-b1a4-c88a86d6ad78",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5f469d9-d401-5020-955e-3d61cb68c033",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:063d7d4b-e4fe-5646-8697-e5411cd40aa2",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f44f7b7-dab8-5982-8d39-5b68ec841ab2",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97441767-5046-5f85-9dbe-86173d907a31",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67250b60-7e7e-5fb6-a7f7-e01dc7966c8e",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1528e9bb-e634-565a-b8d4-6347af5fc87e",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c559a4e-fc78-57e4-91f3-6245ddab2208",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:face1e83-f841-51d8-8868-807fa420bbe9",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c40827-1cd1-51ae-a03c-e97afa5587ea",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e84d8ea-de95-5b43-97ce-048d4252b94f",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0481f665-1d56-5a0c-b76a-7b06d3c5c52b",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72dfc71a-c28a-57c5-b04b-4ebc27262a54",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4f144c3-ddf0-5dc3-853c-df5f4353a4cb",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed27f495-ba78-55b6-aea8-8fc3b0643865",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f08e02a-4a05-5d4e-99b5-58db4e35b639",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103b95a0-53ad-57c6-ad84-1f6b56c50d7d",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73d030a3-169d-51ff-a7f6-3d16d4876d0b",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c59e9bb-8a89-5485-b75d-3ae872fe7d0a",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eaddfb0-03fd-5e25-8fd2-c58fc50a583e",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d3c84a5-a553-5dba-a4c3-0d41163a0ede",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e93a562-7ab2-57e7-8cd0-058de072a793",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d837d26-bf3e-5b69-9bf7-44484bb9e84e",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a87c3a6-a278-50a8-a12c-eb47acfb27cb",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e2751bd-fd28-5bfb-be78-026e9e64324f",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88787d6b-2459-52cc-a968-832a4fa2ec3b",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7858edb-739b-5ce3-842f-5ed539ddee79",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47ea7de9-6b61-5506-9211-aa1749302ff5",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62517a37-ae8c-5764-a191-def46269cb65",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0180930f-683c-5de6-a822-795b050d3113",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0e5b44f-a71c-54c3-b1dd-e4bd458dcb1c",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aa4e093-398c-501b-9ecf-7ce09d97355f",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61ea869c-e18c-5474-8883-ba873f50fcf8",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.6 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.90-tuxcare.6"
    }
  ]
}