{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:65f065af-5cf5-5a59-8dbd-0ccb591b2501",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.29-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:813e1fad-8af5-5c8d-ae76-a3fcc515567a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88ef4c2b-66b9-59e1-9f7e-4d26d98ed427",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:568a654b-ec21-5b61-a8fd-ff09f53aa70f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2f1e5c6-f42a-57f0-b2c2-b91e3a83db6f",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3ff136e-19d8-5908-932b-5e343eedf054",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:372bb75b-fc9f-5763-8f10-ba336ec82ae1",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d9cfef-3da1-5a8f-a419-46d8b5bb0a39",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a718fc-02b1-539f-a5a7-8c47987c81b9",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:639a910c-34f4-5d11-9dbe-12e0b571f3ed",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcb3bc82-f23c-5ab8-9663-8fc30cf55a51",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2dbebdd-0ae2-5660-9a06-4b2b8b3ed92d",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29e2d197-eff2-5870-94d8-d2585caeeca0",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-orm 5.3.29-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d55641-3616-5a44-b86f-93db6b9311d5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:831b6bf0-adf1-5254-b1a9-0ae922d4e49e",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f828f133-cb4b-5992-aad1-1cddf0f726b1",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebd51838-a7bf-5a06-8f03-01481208c3b0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d297bb-5d38-5f0b-9d12-0073b5904671",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.29-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.29-tuxcare.2"
    }
  ]
}