{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:fcc22444-87b9-5f80-992f-84b80a1b4bce",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-security-oauth2-saml",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9fc92c08-d19a-55fb-896b-7f7514ab96d0",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c61c7e1-f167-5857-8987-803d88945c5b",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d00db933-c43c-5fa8-8d6c-8f8b20bce8f6",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48573e5a-8b1c-533f-8fd3-f410b8476400",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23b9ea90-b5e8-52dd-871e-8d54ca01745a",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e96a403d-d6de-578e-b05b-811f89f4f8f0",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8fab923-a74b-5742-8cd2-d88714804719",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:233e3e2a-00f3-5243-a17d-f2f9c07739f0",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b89afe61-2a24-5062-ba07-c2393e1190e5",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2221e6f5-3abe-57bc-b1d1-a0b28ea9231b",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ec9f366-8a44-571e-93bd-ed8887919bdb",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:397caa5c-2b66-54d3-8c3a-5ec3c48aaf3a",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89bf00f8-69dc-5c3e-a75c-f92ff13e10af",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d48c72be-ed78-5729-80f1-733f72462343",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f180720-5a58-53ab-8be9-42ad933debd4",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f2adbfb-5a49-50f3-8df2-9863bb8ce968",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80789a4a-4276-5e38-9f82-689b58e05f4e",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cc89284-7312-5a12-ab68-156f988e18fe",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3568020-5010-5cf5-85a3-9fa6086d0e9b",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d8fafb4-9aee-58b5-98f9-6b7889ee9915",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:569ae0d0-b3f5-57c9-9ec5-9a7869f34c83",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd2556b8-29e6-5b90-83bd-ac13d3f35317",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8e9e997-3df0-5112-a420-e4e19ac8b3a7",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8713cb8c-bd35-56eb-8629-3edd80e7bb26",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16742699-121f-5bc4-b273-69850410ebfd",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ce6540d-26b1-5713-aaf0-3c30b53968d0",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-security-oauth2-saml 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ceaf4407-8de1-5b87-ac50-42b16abe8f1e",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b1a3ff6-e285-5b1d-8566-6d6bdcb3be83",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-rt-rs-security-oauth2-saml 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5ac48f-922f-5afa-9221-b0b1e2b62eef",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:893dfef2-7633-5e8c-b16e-caba701aead4",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-security-oauth2-saml 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:51862e89-a802-5caa-b1ba-29ce022a922d",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a7b12c6-2151-5312-b5b8-b3a9122cfee6",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-rt-rs-security-oauth2-saml."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2-saml@3.5.11-tuxcare.7"
    }
  ]
}