{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:601def1a-b1ff-58b5-a4f1-0ec84bef3c47",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-integration-tracing-brave",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:879ef926-5e4e-5602-a347-415d6b2405fa",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b226368-fca1-562e-95a3-99650e8e949f",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:873f9afb-6500-56a9-bed3-a878680cb6b4",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5306065e-11c9-5437-9340-b4ebafd47c82",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0c5e03c-0e59-5e6c-8e46-a3a3f5c8d5de",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6bab72f3-fa6e-58a9-8991-8b8a6177c466",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2598d59-3d76-5ec7-b317-1e57c1316a92",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94b7e231-6858-59c3-8af2-f23f564500d8",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c9ba823-a778-51a9-adbf-455bd08c9be9",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e2f26d8-2f6d-56f3-a1b0-9b671c5b1d99",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0997e31-9c0a-52d4-a630-ea2e493fa0f0",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ff67ef-c5e3-5048-acbc-1c82c949e59d",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fbeda81b-41ae-505e-8472-0152d8bce86d",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0951a507-43c5-5a57-b44d-ef09ccf2e849",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c43754a-a9ed-5aa4-9aa2-f6719fddf638",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:852fa9df-a89b-5951-bfef-e95d1c966eb7",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab6b0792-35ed-5726-a16d-db2e9b977ed5",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-integration-tracing-brave 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b80b4c1d-14d0-53cf-b4d5-dc9ebcae17d9",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5d42ee8-914b-567e-80c8-a321a15e38f2",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e93c1a70-f360-576c-809c-f77595f0f1a4",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:280f312b-2d06-57f6-a7c8-addfce52fa7b",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9f18b49-9f16-5edc-84ad-6437baac8ef9",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ba7d67a-fa9b-5f47-b545-577b66cbdc8b",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbf62185-a80f-5031-894e-826eda4381cb",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb945872-20ea-5b84-bb43-b865a1194ee1",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:decae135-7e03-5672-9ce8-6e0ae626533d",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-integration-tracing-brave 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36617ad6-b1ce-59e7-9f5e-8a498086c0fb",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:189998d4-4b1a-5cd2-9d21-0b0e88a9d0c3",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf57369d-851d-5cd6-bdb5-31db20692226",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fb6755c5-0a11-57ca-b1e9-f0578fb939fd",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-integration-tracing-brave 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:161cc9ac-9942-5f30-9568-6d8176ecb912",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eece3954-2722-59f7-a0b7-12c9725f5af5",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db4f41b-ca31-5164-ac4b-4c30273853af",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a82e14eb-adb6-59fb-926e-1d0d9ef59055",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-integration-tracing-brave."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-integration-tracing-brave@3.5.9-tuxcare.5"
    }
  ]
}