{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b64705a8-1046-5b59-901d-aa7fd0b3636a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework.security",
      "name": "spring-security-ldap",
      "version": "4.2.12.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d9ab812f-c67d-5c75-b054-63c46ace54dd",
      "id": "CVE-2007-1651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1651 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:809f87a3-cc03-575b-be31-f8b017e9b116",
      "id": "CVE-2007-1652",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1652 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3949700b-a99c-5191-b0c1-beb5b2c0b485",
      "id": "CVE-2019-11272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2019-11272 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c30e2b42-668e-50b7-af6d-9b1d29fbb9d4",
      "id": "CVE-2020-5408",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5408 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12989a54-3659-5304-8408-578ce9eb0b21",
      "id": "CVE-2021-22112",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22112 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f315a121-9c0d-5fb8-bd99-c63fabc98b9c",
      "id": "CVE-2021-22119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22119 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7717177a-4e1b-59b6-92fc-313bbc42912e",
      "id": "CVE-2022-22978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22978 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6a4fca2-e23c-5d64-bd62-38eecc0da36d",
      "id": "CVE-2023-34042",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-34042 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e54c3e3f-29b8-508e-a931-105f7fb21a67",
      "id": "CVE-2024-22257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22257 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c33a4921-2a37-510c-b48c-4be9ca46c3c7",
      "id": "CVE-2024-38821",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38821 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1cc0689-b940-5595-ae07-d48366a2d4a9",
      "id": "CVE-2024-38827",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38827 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0c003bb-8de0-591e-9253-0f480b3bb2b5",
      "id": "CVE-2025-22228",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22228 is fixed in version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:416a4e55-496d-58ab-a9bb-fe8f3ce58ee2",
      "id": "CVE-2026-22732",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22732 affects version 4.2.12.RELEASE-tuxcare.1 of org.springframework.security:spring-security-ldap."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.security/spring-security-ldap@4.2.12.RELEASE-tuxcare.1"
    }
  ]
}