{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:04103d8c-9243-5d57-8b62-32cb6998aace",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-juli",
      "version": "9.0.90-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:cafa1d23-30df-5528-81da-89dd344f80e5",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c16154f-e17c-5f3b-9229-ba2c1d8cae9e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:374cea5c-2b40-5e67-825c-14d39e84ad31",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f80fd751-b0ee-533c-aedf-ba392871492b",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97206fff-16df-55bb-a9d1-444235f4c00e",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a390276-0bfd-5e5b-abdd-6174c6f4deb0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:798be1c7-eeff-5f8a-86c8-09ad339d40f6",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6903c278-e8af-59cb-bd46-ba008a1922ff",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3bcf6fcb-edd6-5aa5-9016-bc74c602dd0d",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83611a6c-9928-5d8c-a914-59970321eb57",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f010dd87-05eb-5f5f-a9b3-5d177f68179f",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c829cb8a-5e43-5a64-9c71-671e887e3dfd",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f89f55e-a52c-50ba-b25c-bdd061ebc5bc",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c45e3511-a282-5d16-8db7-1d11cd1ecc62",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c79368-6a8d-53e1-aaaf-4b0d3b9252a7",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9bb715c5-21db-59fc-b35f-49e0fdce6e3f",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b6255ce-b58b-56aa-8c61-465b25d4a01b",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90458cf6-6498-50ad-9fd1-48a44b90eb15",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:944c727b-1957-5b37-85ea-6beb67e50f4f",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:338a9e7e-d53b-5618-8e38-b2484e9d947b",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0a2b30f-2d93-5e72-bdaa-1eeb619efb38",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a33005-5109-5f13-8f8a-6e0c59cb4a62",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e09577e-798e-57eb-babb-93d8f6c13233",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b33a14a-cc60-536d-b5cc-e80bf1d41bea",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e84c43c-a809-58d5-9acf-e10841253b0b",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:771b3b2c-2a69-5ae4-9531-1b5778cecd13",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9c4c19c-9493-56f4-aaf7-813188c42521",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61a36499-9477-586d-a853-74dfecfbe5bb",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaad6c3e-bdde-569c-a911-55d2d12267c5",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b514e1fe-db28-5ef6-a02f-0587a30204f3",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91826b3d-0374-559d-9239-5c6578a5a8db",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d431ff0-f8aa-5415-b855-0070a8a99744",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7842f517-c09a-52c2-b8b6-e0bf5b865475",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:037e6c5c-a8da-5c59-81f2-d3ca2bf3978c",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cce8eba1-455e-527c-b8a4-304707f3f86c",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:badda600-ad44-5fe3-8b2d-3633cbbcd2fe",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79154818-9de3-533a-abfe-f775187abe82",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1834bb75-953c-514b-83c8-95933ac2f05f",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93f0dbb3-743a-5caf-8177-9e0a4b9201c2",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-juli."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-juli@9.0.90-tuxcare.2"
    }
  ]
}