{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:7c3850c0-642c-5eb6-ba20-a1f02c0aa039",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util-scan",
      "version": "9.0.100-tuxcare.4",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b1698af0-266e-54c8-821c-7b635961fae8",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa149745-b0c5-5488-83f3-8f7cbc4d516e",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4317d996-73c5-5974-9626-032112ae337f",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56274e2f-804d-5f68-b289-8418e6d95eb1",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cc8786a4-4821-5cf2-9244-5cb3b0374b3e",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e12d863e-9d42-58f0-b9f5-a2e9693428c7",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e19c12b-15f4-57a0-8332-69bc1506a1f1",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09eb9ae8-fc4a-5df5-939b-f3f69b3a831a",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd33267a-e118-5229-b396-2ef19112c44b",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05dcac08-5e41-5cf0-8cca-c33349134804",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de154995-3bd0-5bdf-86cb-f4b020f712aa",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0d25e5d-dfcc-5338-8f8a-895abf190b7a",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e6e9de3-add6-54aa-b6c2-06131271fd38",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85e4a688-bd1d-5e51-bd36-d1c20655617a",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3422f1c3-7c05-5529-8f63-6f46e8492a2d",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc4b628-0a9a-508b-9a9e-c02fffbf4982",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96bed7c4-bde2-58e5-9e2d-af880ac6916f",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ef1c00d-8a9a-5375-815c-aa3c1cb2193c",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfaec8c5-ce9a-57b4-869e-bde08dc2ca70",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31534611-fd1e-5c96-ba60-51c390d0ed84",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:835b4ab2-bcff-5588-8b1d-a1b5ea65b97e",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f7b9365-6a8f-5205-8d56-478e4b64045a",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d86e208b-c5e0-59d4-a5e4-1f7705ccf954",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ada9854-31f8-5b1e-8a57-efd8dc7e688e",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a973e7d3-3870-56fb-b6b9-65d2c551784e",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1e8124e-5799-5702-ae74-d66b1479a1e0",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cd8b538-4b09-517b-a6ec-d5af4da383e3",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ad619b-8fdc-5bcf-b063-cf4c16219912",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26a40e74-3e59-5b8b-bd45-dabe8008921a",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed76596a-4c04-5778-8778-cef52bba6c84",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29ba1e55-bfe6-51f8-b13b-2e86c28c8b33",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46fbe850-bd2a-52b9-9de5-2bc1ab0ffa7b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ccaf281-38f3-54fb-ba3d-734a333da60e",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5307c39f-990d-5f5f-b054-bf8019147e96",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d225a712-b521-5b1e-afd1-50f21cacd0ae",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55768ff9-202d-59c2-8c3b-07042f72f0e6",
      "id": "CVE-2026-34500",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34500 affects version 9.0.100-tuxcare.4 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.100-tuxcare.4"
    }
  ]
}