{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:9e5ee341-486d-5d0d-9bb8-b77986ecbdad",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.osgi.itests",
      "name": "org.apache.cxf.osgi.itests-felix",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:946693cd-fa01-5824-8b21-a631b82bc55f",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:582d2567-d484-5d7a-8745-801c85de3a4e",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:284d101f-2fc1-5c5f-b060-52ab6a691878",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10a1b585-98a6-50b9-b2de-547461d6c7db",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9378f01-24d2-5b08-a462-e9cfcc2ad585",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e2af9dd-2a3f-5b0c-8b1e-f1e87702df28",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce7f9048-8876-5161-a2eb-d82f8b6acdf0",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a39356-1aba-5375-adc9-382d8506ab34",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea2984ae-6779-57d3-9f78-11e0758ca23f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e19fdc5a-9a72-51c0-8331-8627888ca3c7",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59747b3f-06f8-594b-baf3-91b2a3c79941",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:148e85fa-5c9a-574e-9ff5-76e92d07f6c7",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:abb2e6d8-58a4-5577-b232-8dfbb870a2c3",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3656425d-c3de-5347-80cd-6ad15169aaae",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:114d1c3f-94dc-5ffa-854f-3556a220f725",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cff496db-b886-5a93-bb6c-1ff1f0820697",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b2f761-716b-5a30-9d0e-097ff31507d6",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c52428e5-b673-581b-9510-1e41d640a263",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f1b8743-5b95-56bc-b720-e793f7ca92db",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1ddf3b7-1d83-53f9-a067-01e3d3ecda16",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07e802e4-4798-5960-a8ed-21b91985a1f4",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ecf12f3-ec1c-5fb1-ae9f-1ba5e6af0035",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdf72cf0-bbd2-57c3-9827-e5719387d8be",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff719f05-f3c9-5d35-ae10-2ca2d51441a3",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cca15cc3-3f66-518d-adde-8214147d4068",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9d6ea9d-8801-569a-aaab-94c7a8fd6109",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c53e356-a135-5215-a4b2-f86b74989c10",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:227503d3-f214-5675-b4c7-7a1a52b95a52",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aaf93f43-a3c7-549c-9d87-a0cc5df7e4be",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:11ba3003-3436-526b-9895-4b2f5d7372fb",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1460f859-1e1e-5228-a6ae-db3509f4f748",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:592105dc-50cd-5241-8943-c9ae272316c0",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2fc63f5-6160-5a81-b00f-bd30dd17ff69",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2d969e6-898f-5c12-9b39-31af2d98d3a8",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.osgi.itests:org.apache.cxf.osgi.itests-felix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.osgi.itests/org.apache.cxf.osgi.itests-felix@3.5.9-tuxcare.5"
    }
  ]
}