{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bfb28c8b-de40-5207-be07-c57b8dc30162",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper-el",
      "version": "9.0.100-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4ef8a4be-daed-5ce9-ae55-c22176870c0f",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fddd09a3-76c3-56e2-801a-ea87fb1c4d2c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89640550-de7f-5d98-a51f-e5f8a2d61a38",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ea13cc2-a2b7-5d1e-a196-2a711fba3554",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:efdd2a15-eee3-5247-a059-2071d16a8bbf",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c04aa484-86d6-595b-be29-2c8d454fca4a",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ebff62c-8e29-5d47-acb7-f4dd60490a01",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a5dad93-08fc-59af-b2ae-bf8d8813f89f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db738d6e-8bfc-59e0-a5c5-e1f426a4538b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13a6fec3-fa97-5fb8-b475-4314ca5adb6f",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0d0c3b7-23a2-50da-8471-4b0dcf0d9936",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79b28ccb-10fa-5466-8b62-a48e8c57c522",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ede0db0c-5085-546d-bad8-a1a1a5a482e4",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ebbea7d-9d38-516c-bac8-f37c0e2f8be6",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85c5d310-8ed0-5f1a-81fe-592b5a6530d4",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd86bab6-5b7c-57b5-9a89-ec576560e19f",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e1bb0d-ea08-5c54-8620-ccefdb232101",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7508170d-bde5-5113-82fe-49f522f127f3",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f67288-d6eb-5301-9f8d-2137f32cf0b2",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9945e9e4-16a7-5ee0-a442-97db50e78bb1",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1775d47b-7163-57cf-b194-dc8d50ff140b",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:785b5426-709e-5e06-aebd-fff6fb45cbe4",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4a427e4-37df-5029-b7fa-af9e7fc0d799",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80d60c9c-17c8-5b2e-a840-d9d5132bc79e",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a36f3b9f-3306-5ab3-a4a1-9a80c8bb2aee",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec416936-6c23-56fe-b4fc-59214785cb96",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3477dc62-bfdf-5200-b59d-18e57d623729",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4007366b-e4fd-5edb-a3e8-f7a77597c4a6",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e62855-bf7d-571b-8eea-553020e8430f",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55b16eae-adec-5b86-b002-a9f1ff4d058a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87f60d89-301e-5c55-9dcc-fe32043308c9",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64ab0d0d-c9a7-5283-a638-fc4a70c3d0f0",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d20a81b-e6e3-59b6-8f2e-36ff18ead18e",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:568d0c6e-2080-50e7-b4d0-2c3bab8eac33",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b062807-0b2a-5a5f-9e30-7945a505e846",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afb1bc12-a5f9-51c5-8f18-6897159c8d5f",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.2 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.100-tuxcare.2"
    }
  ]
}