{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:09da7cfa-d9a4-5d6f-b068-42bb4963c581",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jdbc",
      "version": "9.0.90-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:05aa6561-1ed2-5e99-8b0c-5495c1bebf52",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a3d7042-8093-59ce-9f6e-2fee296ca117",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:953ff691-ae28-5a13-a27e-d5340ea40365",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9583fb2c-3229-5a94-a444-e70c85bb0f68",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c667991-f8c9-5e4d-80d5-c9bfef85ad0f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee724592-2000-5115-80bd-12e3273976d2",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40d1ab08-1b57-512c-a7a0-9d67e554660c",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1404871f-b269-51a7-b94a-b0cd9d1bc82e",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3699b53e-2eb3-53c3-a09e-9e11d9ee2487",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f6595eb-bb33-5287-8892-40021b80917a",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e2a55c1-a7fb-5d83-b2eb-a78a1a124c0c",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9552ae73-41a0-5f43-ad2f-594fe9e8a9b1",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7af5f78-8c55-593c-9356-908b65cfe078",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6a3e0d-0d47-58de-a195-c270084eb089",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2406073a-a531-59c2-afd4-19ff812f92ba",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e41f9b19-cdae-5df4-baf8-559ffc4154d4",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7432d960-0df9-527d-83f7-b38f62d26c09",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11d1e28b-2a6d-5e9c-96fb-4e870992dcbc",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:677b2341-a9c0-5f3b-a209-d3d5f0dcddd4",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cefdef6d-51fc-5c69-99d9-113453361f07",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b19d63e-381c-5821-bfa6-b89719507c38",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84748956-1fcf-56d4-b3f9-bc6fd061041d",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed8c9826-a71d-5344-b485-f4c637642197",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb1ffd9a-6cb6-5b1a-89ae-cf69f96d3b13",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0129d12-ea9f-5fd7-8e19-960b3147d8f8",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f69c02f6-6040-51cf-a2f8-7ba2191f81a1",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9633be1-abff-531f-ac2a-6a080cf5e295",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca19e0e6-d802-54e5-a9ca-7124fd135415",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bd2ddc6-eb30-5dd7-8725-a790be31dc9b",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d89ad225-c9d4-55b9-9b2d-c24495350f9b",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdff7bb8-dc0b-5b89-ab39-405f0c620059",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e1da165-0e12-5f9e-9860-e3f8423248a3",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef5e7e67-ec22-555c-869b-08c6b2081c1a",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2800276-3e10-52f7-85ab-086e6e627709",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e251b824-5cef-5d48-a7c5-265ca623be4d",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b784400-a20b-5f82-b10c-7b55477d167d",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd71c4b5-2c90-5ad0-8881-2db2b288be22",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ada3cd8-98ee-558b-b291-09b0f4641946",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0955af91-aafc-5ddf-b165-5a57115e90fd",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jdbc@9.0.90-tuxcare.2"
    }
  ]
}