{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1e9d94ae-6934-5e5a-b022-e87fd0828ad9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-features",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:fed40bf5-4903-5f59-9a46-09ab122fc822",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67a58ef4-43a1-50bc-b1e2-d573c2a721ed",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e74e221e-eb12-5047-94de-6b34eb061c6b",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee1cf108-3b44-5f66-ae99-04be797449b6",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e16966b1-8264-51f3-ba81-d963298dc03e",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e4009b0-1984-5c97-90d6-ef868fe2548d",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cda2671-bb20-5b39-971e-a4fa109ee6c8",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ada6a45d-c4cb-56ad-b82e-27cf7a3aade2",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6ada7d02-9942-5c4f-9d75-96c826179cd1",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fe5029f-f586-5a84-b832-45140ef99d54",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a76cc46-7404-54ae-a734-fa388253bc23",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2a14db0-2d00-51ec-a838-04b9c5233ed5",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e14f0bd-4208-50e3-86c0-19a9858d1ac3",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b9b5e2b-ffb3-5b6a-848d-29eb82368cac",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4f00949-e0f8-5d69-a7bd-ebbe591101e7",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7889f473-e8a2-5515-8fb2-b3e81bad524e",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:566d7e07-d7b5-536f-b3ff-da3ec356bfbd",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cbf3833-6961-5d2e-a7a1-552e671bce1a",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11aa8bff-30b3-5847-8f33-188d306c61f4",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cbc45c-3a7e-500a-a698-75da499ffb78",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5345e8c-0d56-5e61-8321-72d5169c6ed6",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd92ffdb-2121-5a6c-91d9-30e082d424a8",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab6a59e-8e08-586c-bb6d-2c4605f6598b",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3debf9bb-3164-5354-a621-b4da6ba35e25",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aa727f7-4578-58c9-bcd2-2ba6efac3c38",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ee9f241-11f6-5d91-9e5b-f825c694e954",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0162cb6e-f659-5489-b66d-d344dbe7d8f7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3140d354-bd46-5a37-9df7-c7c26ece7262",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d59386b-a3ae-59e2-9fb1-1ac01413341c",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fa0ac1e-5f30-5466-a562-fee344577390",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-features 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c8a469d-f44b-5f25-90b8-718d8e6ac6e9",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:218c620c-9369-52f5-977b-315b6b113874",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6941c79f-467b-5d37-ba97-9cc01846edbd",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:58ba90ab-17f7-505d-bfa5-08669e5a068f",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-features."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-features@3.5.9-tuxcare.5"
    }
  ]
}