{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c4bc967b-a46a-5f20-8b3b-9bba4e3b375d",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.services.sts.systests",
      "name": "cxf-services-sts-systests-advanced",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:187dc817-0e0d-5e79-b812-bcc00e570669",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e649e590-6d2c-507f-b993-fd65c781bbd5",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:295871a9-196f-52e0-9f71-abe814715a9f",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3012efa-ea8d-5481-a084-f03722997b22",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:176a5108-48d2-5df6-9885-8892a63cfece",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dac053b-d7aa-57bd-ba48-eb6bdeaea0ad",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43019d99-551e-5d11-8342-b8309da1f966",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59758230-f3a8-539c-947b-10f474344a99",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cdd2170-a58f-5710-8a7f-da4fa1c92a90",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cea4894-b5f3-5f2d-9dff-66649bb8eb46",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:757ce102-1ed2-5448-a736-b7fbe311c448",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f361a0c2-6a44-5398-838b-ebaf968ddb57",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f2fe495-c8dc-525f-8cf6-d8126a56ab5e",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e7fe85-ee71-5913-9028-1fcef36dd1b5",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6dc741ab-b02a-5384-9c64-da33b3dd0c3f",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e59fa43-680a-517f-9604-a595d4e36361",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5173165-f182-5728-98d4-5ed6e6cd3a12",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e1b7318-40f7-5d9e-9f3e-cd4833c64b42",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8aad83d9-95ea-54fb-8691-051a23e8740f",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd7556bb-dcb5-5dc0-b842-b518e74f2f50",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e3c7f47-499e-5251-8a14-6ba83d0746a9",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0cedaed7-a46e-54eb-869d-dbf052df6b3d",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a5a56b62-f820-53b5-a6c8-e747f0e4ecb1",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b0168f4-2c63-5002-aa1a-b908516cb9e0",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eabcdca9-0d0e-5d6d-8fdd-5c6416c25179",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cf5f04d-88fd-5608-be7d-59100fd7eb5d",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b57c88df-40ad-56b5-831f-db710a143e90",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:062d5c03-9ca3-5ba5-950b-64149cebe1c0",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72359217-a9ce-585f-ad59-27254b829f24",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c764bf67-85f8-5121-b236-8fe9b42542d4",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9dcee6a-b952-5c97-bf46-f7107cda6114",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f951a7a3-c43d-572f-a7a0-c4832fcad030",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:871240da-2356-544e-8339-b3e074339e75",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43abc99b-b1fc-5944-814b-ce49e3bf2a67",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-advanced."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-advanced@3.5.9-tuxcare.5"
    }
  ]
}