{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a751c285-e8d3-5858-b2f5-755822615caa",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jdbc",
      "version": "9.0.46-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2ae840d0-7261-5a8e-8cef-fb24f1a35625",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8914fcc3-c4e6-52d5-9050-23ee9bd46c5e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1235694f-ef0d-51df-b846-fb550800734f",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec304d5-52d1-514b-82bd-4f42b287a83c",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d83222a2-00ff-5dfa-a26e-6a41863611b8",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1597e9c4-f8d0-5c37-803d-629b62c1c39d",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd694886-1da3-5d33-b71f-a0480914d504",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08350959-3e70-5d08-8b85-96fe590647c0",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84a6e45d-afc0-5569-9fe4-fca320bf6806",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:023b5fd5-ba88-5049-9d25-4d371eaf81fb",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ef10c1-4f1c-597d-9eed-052ea54059a4",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75272fe2-80ac-56f4-9102-e1b19372454d",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39253538-2b24-5ce5-9cfe-1a5e3a4b39d3",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd9ab06e-c6fc-5a30-a707-ddbfcce47caa",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6efd68f5-d66e-54ef-b6fa-55839414b6d5",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67eea55e-ce97-5b72-8b0a-a416271e2c79",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93144799-65ba-5dfd-a1ad-4cb5dafd9f6c",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94133ffd-1bb6-59e2-a353-fe3add61b38f",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c0192c4-568f-581f-b7e6-51b7b3d365f3",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df754a92-d7cb-5e6b-8f9f-084e92195136",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5486fc7e-78e9-585f-add6-0d79428fb5c6",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4d1019b-473f-5746-a964-66566241e34a",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb5076a-f127-59fe-8498-6a4e3f95f411",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b00263a-e01c-50a6-8706-a87ccbb827bd",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b95c696-7bc0-5c79-b009-48f0f0e841cd",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bbc6acf-4575-5782-aee4-73dbaf8b1ead",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d08ab191-36b2-5fcb-8564-f9a14dec5020",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51aabc18-173b-5c8e-8cbe-2ea5556d6a34",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a190a1-34dc-5812-8140-26741cd6bb6f",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd4dd7ea-3c1d-51ae-b6f6-1dbeb2640e10",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ece354e-8311-5fa0-8172-d969eb50d4de",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8222ac9-dec7-57ff-8373-bfd3e32b8aa9",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c32f9931-b9df-5daa-93dc-642bf4d627a0",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d0ecbf7-1d7e-5a18-8e81-2055e7b856af",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7315499-e53a-54ba-829a-6f74ed0b584c",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:916df5f0-5396-508a-a9b8-ca41b56c3a99",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aad03a8c-f19e-54d5-ba49-f41206a5094e",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdd78fb3-437a-5207-ad05-a4c8d1f26563",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b1c5521-6c78-547d-9d51-5dd3d605336a",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce58b253-cb76-55b0-9cc9-55761451c063",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d6d8e27-03a8-5083-9693-a6d8ca4bc3c8",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eceef982-abff-507b-9e76-7ee1ed71acc3",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cc7cff2-c97e-57aa-99dc-67563ab6be93",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4371e8ad-6d03-50bb-a75b-4c9886b1cfe8",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cf86fab-c0b3-597c-8047-fbdbf0f2dbae",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:893300f5-d14c-5d16-aadd-6f5eae7230e7",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:016a08e9-4b99-5584-ba2b-8ad270f93ad6",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb18d6e9-1c3a-5686-a90f-f8d219b839ec",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2f4bbd3-907b-55a6-8c2d-ed3ddcb2f391",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a48043e5-bacb-5d45-9a3d-75de28bf8ce4",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4495ad63-7150-5e8f-acdf-0f7c9bad354c",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.4 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.46-tuxcare.4"
    }
  ]
}