{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e4bb645a-bbc7-533a-811a-bb0c307d2b60",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-spring-boot-starter-jaxrs",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f2eb9565-4296-5408-8323-84375a54b434",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd258424-b652-54e1-9143-996a59c6a069",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71e9f992-4f70-5a78-b18a-98ab1c770d09",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:551c18af-d32a-5dc0-8a89-879bd3057de9",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42be3a06-8558-5c50-a82b-8e1eae430ac8",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03c8e3ba-ed16-5e4b-9223-c2ef54eccef1",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1591bdf4-e638-5e80-bf56-8ef92f02cbf3",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a87e60ad-217c-5653-b070-8d956893d227",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60564236-e52f-5a7d-bc5e-c7d7e4f824e4",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f9508dd-9bca-5bcb-a3a5-ffc7bc9e4615",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:769ca019-2f6b-57b8-9f6b-96e252bd375c",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af0f6ed5-75fc-5d35-b709-76d17beda46b",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ed2b5fe-0dae-5473-bd11-dc13b0a8ce32",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:903d3d5e-a73e-5e45-8bce-e7403d4618ee",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00ecb829-0611-5285-b91e-8777d0a8c0fb",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae54d12a-f442-505d-83d9-a204a2bf4a62",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8241f085-20ca-5f03-a216-a18cb3d06d2e",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxrs 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f5bb82f-e030-59e7-b0e3-22c49b9d5936",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47b00a15-9010-51af-8619-e9fe0a0405b5",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74cdb88-9a34-51b0-a676-d3bb077ba009",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:735fd19c-a485-530e-9fe0-7980cec5f3b2",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60efa3a5-2429-5243-820c-1294dc720bfa",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a667eb29-41f1-54b3-a31d-cde8f15e9f05",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78b0fc8a-633e-5f19-ab89-549bf2093c08",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22912418-8d67-541e-b1a7-07f1b0651313",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6cbd41be-31a1-5662-8393-9e34adb52ac2",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxrs 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6a95c08-8858-5320-9d87-f22c7f5594dd",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9aedbf8-27ea-53b5-84de-0cc2315daeaf",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f58f8f7-85b1-5062-b5cd-13d96a8daec9",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ebd0eab-b248-5c4b-bef2-137a64018ebf",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-spring-boot-starter-jaxrs 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc794042-64df-5274-83e5-b4f56c7da252",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:096cc611-7b61-5b84-8132-604701ef7585",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8fb0478-735b-594e-a7de-4480c459dc6e",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2a1056a-301b-533d-953a-cb82b1cd6500",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-spring-boot-starter-jaxrs."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-spring-boot-starter-jaxrs@3.5.9-tuxcare.5"
    }
  ]
}