{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:95c2c35f-32d0-5cae-9d80-3cca4e34f56c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-spring-boot",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1b9df10f-e212-593a-8626-59020948d1cb",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12bfb020-a952-5584-a81f-243c3627ec9b",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d4f81d7-73df-5b7c-b373-6309c7439997",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:262e14d4-73c0-51ff-81ce-807dcce3ecda",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8efe7c55-6947-54a9-a29f-6b5151b99f5d",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4ea1b72-5390-5581-98b2-4516d255c075",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8311c37d-9f4e-5093-86e6-56dc48a89f34",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7837621-6f5a-5344-b1c8-eab0c0dc2964",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3f4cff-1ce9-559a-ba07-6e050f2db94c",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f685a52-5753-5052-8969-5b5513b28e75",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:555ef3d2-dd83-5ee4-8bda-1e1d451ca085",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09961406-44c4-5ed2-9cb7-1f109907e14f",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2bf2537-22fe-5f9d-a78e-c4b1dbcbc0d6",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b044141-46da-56d6-a282-dc6393dfe320",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcada356-255c-5e1a-a105-e6074ec33413",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a30ab5b-9f13-5d6b-921e-c590e0d1bf28",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c5b72887-41b0-502c-baa6-b128b1a40cfe",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c45e0838-cd6c-57dc-9446-0b5c55050940",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d5d3e46-bb36-52c2-b286-460141dadf62",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46749bd1-e709-5a9a-92aa-03ead1d551c8",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4603cfcb-6913-57d5-918d-d0f6a75c9767",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5edfc34f-b0ec-520e-8c97-31fe430b4cd9",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4700c38-b3dd-58e3-97d7-4ade229e6577",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9dc17d6-b4da-5a03-a998-a0a579473476",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15032c5b-1d0b-5d50-931f-2691aba4dd0c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ecc274f-1676-58e9-a109-163f0ec2dfea",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-spring-boot 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08f7ba98-2a0b-5f87-8101-5c8a060fcbf7",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28e3ca11-3d56-5c2e-9576-0883d3797c2b",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-integration-spring-boot 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdcabf64-b959-52d5-9ccd-5dd624efcf4e",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a3270bc-e2c6-5b81-8782-3afcaaad17ea",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-spring-boot 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4a163557-6c11-5031-a945-ef86b2d33142",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f684a2b2-60fa-5205-81c9-9c2bfa5d0c15",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-integration-spring-boot."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-spring-boot@3.5.11-tuxcare.7"
    }
  ]
}