{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fe8f3f33-116e-58a2-8ab1-0e459c257a59",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jaspic-api",
      "version": "9.0.90-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:114f403b-350d-584d-81a7-e564f5e5587c",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a89cc98-f604-523b-ab09-1a6803a9a6f4",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45801f7b-27b4-51ed-a3cc-95cee4d94f2d",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbd01915-0233-5cc1-9401-25ad26cd38de",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca9d97a9-f908-5f79-8055-2d7e803744cd",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad7c1259-8ada-5ad2-8405-3af5d3d713cb",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1f9d2be-9a15-5f6a-91c5-f160a912c725",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daba4869-4fcf-53e6-8f7b-dd8c6ff31637",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dff429b-56e0-511e-b84e-5edeefae391d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:879bdd66-4061-5b22-b20a-f4aec6980035",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c3dec95-7b28-5d94-a038-bb387bfcb436",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ac9e830-4c0c-5350-9f01-8aea3b365eb3",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9fb6c76-19ea-5c8d-86c4-d8243052ce91",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32c0b6f2-c88f-5f42-9e5a-7b4cd97d7cdf",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c5ae653-f4aa-5cae-bb86-3b9bc9575f72",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6b285ba-0b48-5709-80ac-c47993c58082",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d86a546-62fe-5c1d-8fb6-9dcaa538fc71",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1886fdba-fa20-5232-8835-753cb319138f",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86f951e-2651-56f3-a855-4e80644eb5f9",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06aa5fdb-29bd-5d1e-8a43-4cb4e6f2fee7",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7206042-80a9-5210-aa60-91d4c355e2a2",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c3067f4-cd65-559a-87af-f00a66fb5dcd",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b397c248-a900-5f61-ba3f-27d7e140a8e4",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1840670-6036-5e8d-b066-eed56261a428",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a48dafa-b834-511d-9520-b7711de1ee70",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:768ac3bc-2d46-5479-8523-e4a1df4b0ecb",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef3e9df-26df-50cf-b253-1a423b885091",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f57d184f-7abd-5fb0-9284-64cb36e2c016",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7c92054-6416-54c6-915d-779860f8e428",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c645b9dd-df3e-5341-9479-a7e6634bd1ff",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f40b3742-c552-5db4-8a98-72e35cc4d0ff",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:592db404-32c8-5ab4-a357-fee7ac7924cc",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c203ff44-b9d5-5541-aabc-624360b16920",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ffe97b7-9399-549a-8dae-44404c11fb48",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f9b6eb4-764b-5bad-bc80-a8cfa3de2602",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3869176f-ef5b-5a0d-8d95-b7007b0f5864",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f004ede6-e756-5a3e-acde-6825cf62dc0d",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:705dc000-a979-5f16-94aa-269b8084f3c5",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc8af301-9c32-5efc-84ea-912113bb8116",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jaspic-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jaspic-api@9.0.90-tuxcare.2"
    }
  ]
}