{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9829697b-cea9-5f37-8632-c03193329355",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper-el",
      "version": "9.0.90-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ac664b30-31ff-5220-bf37-e4ae7c06f36c",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:13d96149-14d7-50bf-85a3-54bd3dd68c2d",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d3fc44d-c5dd-5eec-897b-c616b8f57802",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec5c1423-a872-5fef-bc71-abac0a693403",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e21b9a-a85b-500a-b8ea-a8eaf25b3f36",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57112c6c-2e87-53e8-a99f-692c845f7c84",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2e50b10-8824-57f3-93c5-829dd59c1c11",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd667b2a-d081-52f5-be8e-2032b472317b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c1e9dd5-65ac-5e8a-80d5-cb00a7a9dcc1",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7290660e-6ead-5b68-ac71-ea2aae8b8c61",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c434b5-8fdb-5a07-b198-aff23983e91a",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09c6afb6-d1f3-5ee3-aa0b-76d498ec6de9",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9bb0053-9182-5b6d-ad0b-c72b9600eddd",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18408834-104f-52c4-aad6-2d17a2e89319",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e91327eb-d998-54e8-9de6-c59ad7c24bfb",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2af6a37-a22f-5c94-ae7f-f79bc0d05100",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e920ef7-48b7-5d02-950c-9b700742665f",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a382937-9934-5271-b175-e2358837074d",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:408f2415-2e3b-5154-8ec7-0189c094be6d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c46ea14d-8d81-5071-a955-d2c0d10fd50d",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:947e5a2c-4517-5d17-b98e-6685f3ee70f1",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ba981f1-489b-55d2-b2de-32168603e8c3",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f87a25b-b1b1-5a07-bc39-8dd2319f4b20",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a4cb2e5-a583-52d2-81c3-4cf0cd8896de",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78e09c95-4057-584f-bc96-1f2a16ebb8c4",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aa4d8a3-3508-5e42-a765-1f98367e8d3c",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:541d008c-b980-50b2-976e-cf3c191fd4f0",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e680ed9-27b7-5cda-9015-2926d1ebdbb2",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:413d0f04-7514-5b50-9bd1-b27539b3c9a6",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:505b67a7-d002-530f-8319-565dada74788",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23b5e441-4e46-507e-8931-a813064b5675",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71da5d97-f8fe-5e27-b9af-4405fd97e31e",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3199bb0c-bec2-575c-8be9-aa09ac6f0016",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0de3320a-be97-534e-925f-f2219464c62b",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35fd20f5-a735-5e40-b28e-3e9fc69a3076",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac60f11e-c79d-5f1d-b8a1-73933d9bdfd7",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0df53e1-6d89-5c22-bbb6-9d7a766baff8",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05e6e185-c6e7-5f85-8dd8-340ea902d743",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:068f1c5d-319d-51fc-8cf5-557e81678d1f",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@9.0.90-tuxcare.4"
    }
  ]
}