{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f9fde6df-9630-5c79-84bc-8f8278cbe177",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util-scan",
      "version": "9.0.90-tuxcare.2",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:768e2d43-7dc1-5464-82ab-8041617a5fd6",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:520ed4bb-9dd6-5029-ad71-cea0abf34ae3",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34dc3e91-2bf6-5d2c-b4ed-cbab85a600b0",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bdf80ff-1f2b-5bfe-8343-35c2a45647a2",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:935d18ee-f374-50da-b486-22b5a732f8f7",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7f0c73fc-3053-5d0e-a2bc-cfbd9e27d569",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67f81bc5-2023-5c1f-ace4-16d2ea83cfce",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71577904-a4cf-596a-a560-93f8199d59d9",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cbe95d8-7f02-5605-9c1e-a8c4b4b9b8c6",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:505ef41c-5476-530e-83fe-e04e62d3ed1e",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de8a08b9-ed01-5c32-a3c2-6ab3a30ba6cf",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f802d25-9548-5a0e-a614-853a214007e8",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:799e24bf-59c3-5e1f-99e2-9e016cd03b9e",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69f445ba-470a-532b-b4b1-e0c9a080548c",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c184c501-e8b4-5353-a087-a491149ffb19",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fdde3b1e-bac7-50fa-b691-947fc494e680",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c7b519f-e8d2-5422-983a-871c0142cebd",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c62bbe4a-aad1-567e-a73c-57a3ccc0fc82",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:125aeeec-fe4a-5923-a873-1bf92a09b29a",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23efa884-d282-5c3d-a89a-031a2332a295",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cb38436-e7b4-5285-a8e9-737bac7bf205",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5625d97-b56a-52e3-821a-4bae10693208",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2f862a3-9377-5a30-8e20-f069ed052d51",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da96ae2e-57f9-5434-963a-8ae7a330ebd4",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2292dae-cba4-5b87-86d4-e3ed25b196c6",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d597f93-0e57-597e-a214-2b04b82f8401",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24cfeb46-8fe6-5a49-a007-edc769b7cdc0",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9201b2c-521d-5e54-98c3-a52d3db96285",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a879c91-8d73-5310-a306-f080b2f465be",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:468d3c7d-544f-53fd-936c-bed9feae8679",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70d8868e-b22b-58fe-83f0-3fecda97e544",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ea17685-350f-5d1f-9ec8-6671afd377ea",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0feacba-1ea9-567c-9d44-15770d98e0fb",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a97d64d0-4a4a-596d-a823-ce143fbbd40f",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:476fc112-4675-522d-beac-b1efb936b65d",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5526f725-91f5-5cd6-be6c-dd81041cd17b",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:242cd50e-f3a2-5949-a61c-4ce0cc821b9f",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca08401a-aa02-5f0d-a747-d389a5dbed55",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51b1dbda-f2dd-5792-abea-933f23d01945",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.90-tuxcare.2 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.2"
    }
  ]
}