{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:93d0588e-a428-55b6-a969-7d981c190675",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-bundle-compatible",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a1257bce-9985-5f5a-988b-ed85396ca55b",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:debf8235-f403-50eb-8c92-9f08dc22566c",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:674d31a4-1eb3-5380-9e49-a331477a334e",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7c308a5-0b17-577a-ba38-7f9e676da4ef",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d03ab25-0285-5216-84c9-d28ddf822bc9",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65e533b6-22fe-5044-8282-975c44e70941",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30e8ef66-a989-52e2-aa0a-bcaf67bb5567",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:724a97ee-c53c-5bd7-b03e-4025f1aa82c3",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:420a73da-4f9c-50a5-ba97-fc4f07c63f83",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a3edbfdf-4c0b-5a32-b14b-448d5c81e8eb",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b8379cd-1ef6-577e-991a-48b4063dd70a",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10955716-3537-503e-a060-3ba1f4cfba82",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6eb1a007-9954-5bb5-b26b-c3c8934d3c7a",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76244e1b-1ba0-5736-b960-fa747b7e6dcd",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99fb31ba-66b1-5ebc-871d-e7a8f961cdf5",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8f50ee7-137e-519c-9e77-d3b15520986d",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96258eb5-0899-52b0-9783-dae09c8daefd",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-bundle-compatible 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f3adc18-8044-531a-b040-7e4f70fa046a",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b1980b9-6cb2-505d-ac22-7a4aadeb2834",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73fde2ad-e34d-5cef-8aa9-8c3bd888886e",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43b993b3-fb99-5630-95fa-e2274f600f1e",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a0fd468-099b-5d10-b199-e57e86aa853c",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31add17b-62f3-5658-a350-37d30f516d26",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec4d485b-fe84-5582-8265-54965ecc73a3",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7b3dda7-9ff6-590d-8aad-3a9af32c0b21",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c8f7be4-077b-55fd-9ae8-169ed2222ac6",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-bundle-compatible 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:16c31f0b-4035-5992-94f5-caf19090c9de",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e56c857f-a8a8-58a0-a211-fa8c5912604c",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83e5fc70-ffbb-584f-bc4e-803f5a7674e6",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75141887-0452-56a2-8b82-fd69e43c1399",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-bundle-compatible 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80e89539-3098-5bc8-a94c-5fc11797202a",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc7600a5-2334-5e35-bf60-1e4cbb4b51e8",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03093332-0567-56b9-9039-be44c1013b60",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e489cadc-1a64-55d6-8d73-a4bc300bebad",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-bundle-compatible."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-bundle-compatible@3.5.9-tuxcare.5"
    }
  ]
}