{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3259b9e7-6390-5407-8401-0c3151550f85",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-tribes",
      "version": "9.0.90-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:0fda1c53-955d-50d1-9dc6-5c64a79f838a",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d932131b-b448-554d-9c11-b8231ccfe13e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a05f8a1a-6f23-588a-9f97-bfe725371126",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e18d5eb4-180c-5e11-8eff-5998b5f6e853",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee33c951-0877-55a2-9175-392002b5a002",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f728861c-29c3-5093-941c-6d25cd30b264",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6549d0b7-2099-55dc-8d39-5c83bd07c144",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf72e5c9-d13c-5ac1-a19f-7b4c7d8ed6c3",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ee9a58b-70c8-50b2-bd27-0cdc6b4a6579",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6411392f-f4d4-5448-a8ad-f53ba207e31d",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43e810d4-6e7f-50b6-b2cd-792f25e3e36b",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3582482d-6e04-5ed2-a7f2-7a638be92e7b",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03f03068-e801-5c49-83f4-c65ebda3ed6f",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11eeb9b6-d4c2-52dd-ab29-71132193429d",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ba70fd0-39c1-5032-a233-b4cdb0501fbb",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b776d1e-2520-511e-9555-5cf61abde2d6",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52308f4c-ee8f-520d-a648-1649321b9769",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8c5d498-aa38-5995-9c9b-c0eecaa91e35",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42f32df9-bef9-5899-930e-114f187eb40b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b7b8e2-ee9d-557d-80fa-7ae396e23d49",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89a0667f-7cd1-5f21-9840-e2043843b120",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d6cd160-8f71-5e79-ba82-62a17db91f6e",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33ae883b-6430-54bb-8bc1-7f227a853793",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d7dcbb1-56d9-5856-b724-5d6faa86d3f0",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a360e4f-ee7b-5d4e-81f4-54239f810313",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29402e81-554c-55e4-a7c7-c05ebc56d28b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:218887a9-422d-5e1d-8e63-aa054d12ea2d",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6859655-3478-5748-acfc-d74b41c5e7d0",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97076183-d149-55da-a26b-a548dfe9deaa",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:318d6d2c-2632-5692-9afd-28f117263d3e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1fac3882-cf96-5f75-9b37-16cb8d19778e",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3dca1653-a5d7-5e96-93dd-9afdfc6bf923",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d064a838-a386-5ecf-87d5-11e620ee2553",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6e51eda-55ff-5f90-9f31-390a52af47b0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96084add-e30c-582a-9ffb-92c9a1e533a4",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73edab33-d6c0-5846-aea1-48e1daac30d7",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96a932b2-17db-5945-af12-fad03018561d",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a32e134-b054-51fc-a11f-67c25eff4108",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4582c00-9c6d-58cd-8c66-926109816df4",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.4 of org.apache.tomcat:tomcat-tribes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-tribes@9.0.90-tuxcare.4"
    }
  ]
}