{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1c3dc216-d3ef-5800-ad07-2a36250e64f2",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.7-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:95b6f930-22eb-5079-b7fa-c522bb1f510a",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81cef420-7e0e-557c-8726-090c4fc21d10",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ac6e1bc-8223-581f-8971-3dadcce9da3c",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2da9770d-5cc2-5f26-9912-bc3401212dd5",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f82d7b-58de-5543-b564-7091d6271323",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a651cecc-3fe8-5ff5-bf38-b76955e9441a",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff1e6ac3-9755-511e-ac7f-619bd4147c7f",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0413666-3ff4-519f-8175-6bb8f94d7959",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed3c0edd-dda4-5aba-8513-02c212764cfc",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20860 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30e884bb-c709-5fe8-a1a4-16f27ddb9e24",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a17b57bd-c76e-56ee-8760-a0b46fdfe6b1",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d348360-bd11-5a56-b8ec-e5a289ec94cf",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:456df1c4-e27a-5b8b-823a-278bbf06d308",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bf3d9de-ccf2-58f8-8f4b-369d8af91df8",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:faeda8c9-ab34-54cf-9719-14557769d711",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23fee197-b51a-53e7-ba48-e93895168748",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fc67f9b-caf8-513c-9f86-4516c2732750",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52ed3c74-cecc-50fd-bd1f-6266f0681bd2",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b7e6c02-f84a-5310-a4d6-efd2d6433c48",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a78a2db-a368-5397-b2e3-d84fb861b312",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38828 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d5fa696-b517-568b-a1d2-ff4c0eff4a0b",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93d98c3f-7f57-5b71-9f53-23407f918631",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-41234 is a false positive for org.springframework:spring-orm 5.3.7-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75919ce6-0253-5541-a26f-07483612454e",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c969ac3e-b139-5a61-9167-1725f4e8a624",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d78451f-5fb7-5679-ba85-cabf7becc47b",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5005ce5-1585-584f-a8c3-91ec0acaab06",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1faeb9db-c7dc-5dfd-b25c-dee84946dbce",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.7-tuxcare.1"
    }
  ]
}