{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9741c138-4442-5b92-bc10-ba3b1b588db6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-storeconfig",
      "version": "9.0.90-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9a11ec39-3588-5060-a9de-5f665bb49379",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47a27941-113a-5928-bb8d-b907adb01568",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:022f598b-8044-588e-8f7f-41f289daac10",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43d80803-0d31-5697-a924-1637826089ac",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0e5a08c-f240-5469-a564-2ccd0125c94f",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1764dc-9747-5414-a9e8-1046295391d2",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:681f4094-f8cc-52de-9c7d-b249ac9ba4e8",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93625c4a-d3d0-5f8b-8918-4daac9fb1ef4",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5cae592e-63ed-5528-8ca9-a042ded15e3e",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5837354-01d8-5d60-8eb0-52c395c4c15e",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:012889ac-2a7b-59f0-9295-6f1154ec1173",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26c391af-c377-5e32-ab8a-abbfda9544dd",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7323f809-8270-568e-bab3-4393e362e3f2",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b17b0fa-7ff5-55f3-8963-532e58c01362",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1f23df1-6941-59db-8ace-675e37f80f8e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ac2c951-db7d-54c4-8d0e-9a526bab873a",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a2879c1-dfb8-5376-aa3f-4254276bc51a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29fd7812-399f-501a-8a85-3fcb760ad9da",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a90f040c-cade-5987-bd29-163b6d361b2e",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dea874c5-cb67-5eee-b1d5-7122614add20",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83a43946-d7ba-5966-bfb0-aa5643677c01",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25136a08-d1b3-5ec3-8dc3-acad3ffea2af",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d7375b1-6eb0-5e99-abf9-2cee7dbb2efb",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a97f99da-7a2e-526b-a637-b313f69e0741",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88e09003-361f-55e1-ba80-61a5f9d768a3",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:691e4a34-bbf7-5578-a873-43788ff7066a",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ffe6ffa-cf4f-50c2-acaf-4462da3124b3",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b782ce8b-f6d2-5ed9-a736-4eb6806ebb13",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27d8e505-6615-5d2b-9d8b-36d1e4814a7d",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0401000d-dd5b-5497-9c0c-cce57879dce2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a7a5701-ebf9-5573-aa99-976e852770af",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e5abdb0-ec62-5623-acff-022b14a1d19e",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a12f9cf-82b2-5545-89e0-e97239b4f99e",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b38ee96-2a56-5dac-9192-1e41a210cb3a",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e78455bb-357e-57af-860e-71087f12c256",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65033495-2ced-53c6-842c-66b26eef18ae",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3772562-8a86-599c-94f4-a20cb613995c",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c2125d6-51d6-54b2-b25e-867f48212641",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43ae1e76-85da-53e8-9868-a756179854ea",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.3 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.3"
    }
  ]
}