{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6b8f84a4-9224-54b9-8a98-3be9f5f19485",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper",
      "version": "9.0.100-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4075cd47-0b1f-50b0-9a8f-116cce3e1737",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8582f8e-fd33-5fc5-a663-622594d3059c",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f18cbdf7-f24f-5115-8f45-b1b270a470da",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d951b63-d3ab-5923-97b4-99513b22708d",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56ee6fab-edc8-5430-af96-754d7ae05968",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c3897f2-cc66-571b-a101-f1681ae5db1d",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:872f9d54-506f-5edb-a9ee-000003c6a826",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94f70412-c2c0-550e-8a7a-46401aab3216",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f7e2b81-c7c0-5e3e-86c0-dd90bfa917b7",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db491b7d-995e-5a04-9fba-3993002fb805",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbef2b0e-6050-5720-8619-5cdc8fc5fc0f",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f3e688a-0cf1-50c9-a2af-1a7818c50158",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03522be7-2e3a-57e4-a5a7-0f93974f5a8d",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b0ef854-ac71-537e-958a-885200ea80ec",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3662047-3c7b-51d5-92c3-1b6722bed014",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e89bde14-0cbe-5cd1-98d1-b09ca4214fe9",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:53081b88-b03a-5295-b4f2-f10048f23aa9",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d479894-428b-5646-bf76-995ec6ee8b4a",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0cac320-ab5e-581d-af4e-71afe881f980",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfcbd65-29a9-5737-b522-6cd85dbd5788",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4da397f4-aa8b-5467-b3d6-eee98305b4c5",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2654f37-0dac-5d3f-ac36-835ac0f1746b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7edcf2e-fa59-56e1-a28a-35535ffb8081",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c0b3f4-2335-5d5d-b9aa-b2b7a451c6e5",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc348183-20c3-5672-990f-1aa8d3b3f9cd",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:348b4d5d-4737-5762-b43c-75e8118a840e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85291daa-3511-5649-8010-8703a68b70aa",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ac0d1c6c-a4ad-55d3-bbe8-5c9d018e9459",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0110b225-2e5f-536f-8ac7-6a3c1f801ff9",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25d0bd73-68fb-5ac8-ba4f-63ae632b4e34",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21189ba8-3b0e-5045-bd54-c1eb84d13d23",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89f3bb45-41eb-56f9-af9d-8df3f9556e96",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:699c5c30-885d-521a-b3ba-f90dc4dc02ae",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473c02b8-cb34-57f9-a891-7c3d83cbf489",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29f3ee1f-3736-508f-8596-6d92f3bb193e",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9cebfc5-256e-57c1-a65e-b3b5b730ec64",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.100-tuxcare.3"
    }
  ]
}