{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:bf35db9d-fac7-5764-b95f-d367300cbda4",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jaspic-api",
      "version": "9.0.87-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dfd27653-6603-535f-88ea-e13c15fa161f",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12a58878-56fc-538d-9852-402e62163c65",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d2e4252-ab65-5742-9f42-f5a60623dacf",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:382f0646-04f0-5246-8d99-e1ae0546c653",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e5313c9-085c-564c-a50c-10eea616f2f9",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97338743-4599-594f-b5a9-24d35d37bd66",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91e43029-6f5d-578d-b1c7-d32489d17851",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67cf64ae-f7a5-5725-91ac-6a87e812de1e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64196abb-c820-5de3-abd4-5d9bb885e621",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cabc3231-812a-5ac4-acb1-5a6a9c258de5",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8db02c65-a25f-5933-a3e8-2e482cd1ad57",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5e35d9d-5416-5b85-a8bb-759af5fe95fe",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb18f1ee-bc45-57b8-93c3-6d10f1e39ebc",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a428f1a2-291d-5c80-9af0-bfc905691cb3",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9fa7c4d-95c8-519a-a208-7cd618d76c61",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1661049-f613-5ea0-b3e5-f8318394a677",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff923652-d2f3-54e2-aacb-7a8461a29f93",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a8f977a-2092-52a9-a7a4-c8f9f7429a90",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46bf004a-e993-51eb-b80b-1c1a76f57588",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58991ae1-6d82-5a4c-a3c3-d35b39d252d9",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00253acf-ec41-5eca-9718-d36401c40776",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df9bcdc-7806-5978-a0ff-cee41f7bea8f",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ec33f20-5d39-5726-91a0-cffba2e81ef9",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb2c0d44-98ca-5b45-9a6b-5da35a5b386c",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85bf59a8-707f-521c-a7e8-bdb47c23d259",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb9326ee-3d87-5ac6-aa96-e1023b14322d",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c436325d-bff1-5537-a90d-21a7887c5948",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5501041-3913-5a7d-84ab-e30ed86fe32c",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:270166ea-9b12-59c3-9bf8-3e4359c93a72",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3efd190-d69d-52c8-9edc-fbda8359c755",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d43e87-bf4c-5595-aa1e-fa51b6f986c1",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06f496e8-aeaa-5b84-ab09-5d7096a4328b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c2e6350-5675-5304-8a32-4616e1e38e10",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbb3e852-fb5b-5c7a-95d1-6f2dd90e2e52",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcedbd85-1e2a-5712-9214-1823ae3696a3",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e56b08e-44e6-5fa1-82ab-be82a083b8a0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75ebbad-89e8-589d-8ead-0993abee99e0",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:768f73f1-8447-54a5-9bfc-ff81e10825c5",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e25df5a1-9e01-5eba-958a-dfb2cc7903e9",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9930b5d6-e824-5a39-a029-5f141b2d4dba",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d73a5d00-76c9-5009-a8bd-9819b706ac77",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.87-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.87-tuxcare.2"
    }
  ]
}