{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:f048a749-68bb-583e-bc00-700932b6b2ba",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.karaf",
      "name": "apache-cxf",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:976172fe-76d3-5324-be40-c3c37c037ddd",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b1247d60-9c35-5ba3-b0fd-e1c1b648a61b",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:898d948d-d73d-50f2-9e44-33b6b6c02e5e",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:044201bf-4851-5f4c-813f-fe2faa988117",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:427b131b-8361-5abb-9f16-3a20bfb313ca",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd509090-f58a-57b7-9cd8-0968b87d94a2",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8105f7a8-95b9-55e8-998d-86e7a06adcdc",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f340fa98-e760-52b7-9316-e8ee4364f806",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea2f0260-9e8a-562e-862a-42e044ba9d4b",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c53d550f-2496-59b5-9af0-4098fb955a0e",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2c02439-4ea4-543e-ab9d-d401b17a0d2e",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e51cf90-9a82-5183-bd98-21d79a00d28f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6ba8ff7-4672-59f9-919e-3720fdd4a4c0",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7d20795-55dd-5374-8fde-a87ca4a03914",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81870220-981e-5a01-85b7-ec698b45dfdc",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2674fcf5-943c-5d55-b260-fd8ebc2e27d3",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bde2427f-ea74-51bb-ad6a-7c8b8f963215",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.karaf:apache-cxf 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1cb6cc61-0010-583e-a91b-31c0fce9ae71",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d0b011f-607c-5709-b20f-0a2f3c459452",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a77bc271-6842-5c80-abd6-459da5d4308b",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a982c750-f966-5fc0-b3a2-9b35f8b84a4c",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7920197e-5900-5cc4-9522-a7ed27902af7",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63888b84-23af-57b9-b6d9-8652417d19ea",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7491058c-a7de-515d-a009-ed7e1f26f565",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ecb91399-d094-5a23-8dda-c0f521529244",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd677414-fe89-5293-9366-f86c7f6b809c",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.karaf:apache-cxf 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:136b250e-7d7e-517a-ac3c-231b5cf53cbe",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c05d0609-eafd-5826-b532-b7afbc4197d0",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6a608c-765b-5179-9868-ab4d9e843790",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38f107f7-d085-5f34-8400-8a37931d6731",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.karaf:apache-cxf 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07530044-400d-5925-b012-efede7474166",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12c0bf12-d741-5d8b-ad89-1badee21eb01",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3c16efb-001d-5e8e-a170-b8b3de67a2aa",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:973d3598-e4d3-5501-b62e-4d68e8c071bc",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.karaf:apache-cxf."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.karaf/apache-cxf@3.5.9-tuxcare.5"
    }
  ]
}