{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54345209-94de-596f-8678-a069f4b9784b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper",
      "version": "9.0.87-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:87245bfb-31f7-523d-bf42-5e70ebe47176",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f41c676f-2663-5c08-86d1-b4c1b7888a21",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42795224-613b-5801-92d3-90137b509fb7",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fd210ae-45d9-546a-8b2c-7d78a462a8f5",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b887a66d-8cc8-5969-b0fa-47849a3dd566",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a50dd1a7-50f4-5717-8a73-298eecbd5e8d",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3e8bb30-fccd-5843-b4ec-92cb1449a51e",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18583cb2-0673-5a91-a1b8-920f8366d649",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5c620a0-80b6-57a8-9202-06f6a1000b11",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6b1382f-edd0-5980-8759-2d72c3b1bae8",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88a386bf-f979-5f0f-be63-78e21be67fc6",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c588df83-739d-594b-aa7a-7e00ed6153dc",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04aeb176-5b80-5e7c-8e99-0d9b59ea0d18",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:889e973a-e671-5b67-8208-a9f289177994",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a54b1f53-1478-534c-8717-ee0e62f226f7",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d077251c-30e4-5407-a119-67a620355c8a",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f79aa24f-bd08-59b2-a97b-656c9524f56c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6da271db-34b1-5bb8-8748-630d43bab1cc",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a20590b2-a2f6-5793-bf47-7fab53f936a3",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4e0d8d2-e820-56d7-8c74-7c8e845826eb",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe38c2c5-b79e-533a-a758-8596e2d84ada",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29059a28-11c8-54c8-94ad-a2f3c41633bb",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b90f4561-2fa7-5520-8337-1c390990098b",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0146d992-d225-57af-8aeb-560092a3c9af",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c56b7262-6a32-5e11-907d-6c9efa1822b4",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28a67726-5485-51ea-8f89-7975d7e398be",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7dce623-ed76-54b2-81b7-8891f2c877d8",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e463d6-d1f0-5af3-b8a9-d8c43fdb0f3b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e8bb4b1-97b4-5112-82af-24202d231eb5",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ca7f09-6331-5c07-9d4f-778187572863",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4047fbb-01a2-5426-b10f-3f92621c474b",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c9448c8-a0e7-54f0-b7ab-18b1b6c0e8f1",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52d01553-5232-568d-aa5d-28ce1970fd19",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74cce49-6af5-5e8d-a6cd-a7d9aba1ab8b",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24945cdc-4919-5afc-bc95-2f0894e9c8bd",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f71e4509-7163-556f-80f4-7ef2d5353c08",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc5ae2ba-43b3-5e80-9837-b540cc5fe669",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c543f44e-4887-55a1-9e83-41e0c9e20b1a",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3f2f4e6-1451-54bd-913b-f78bc1675e16",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:432fa781-6b06-5067-84c1-244236f1dd1d",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3065d0d8-eba0-502d-9dd7-de71493bd4d1",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.3 of org.apache.tomcat:tomcat-jasper."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper@9.0.87-tuxcare.3"
    }
  ]
}