{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dd623809-cfc4-53fa-aada-3b8b63f10359",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.services.sts.systests",
      "name": "cxf-services-sts-systests-osgi",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:52a98540-d34d-5979-84a4-24ec77d557d7",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c2ee2b-9fee-5593-9a9b-f2a7b2776bc9",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daf14c75-1b72-53a5-bc95-46c272cba269",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fec7149-adc2-5a13-a839-f261b330cb40",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdf5e12e-863e-5a24-bcc4-73e48cbe1d87",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf85d4a2-1577-529b-a9c3-952995c9a95d",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8cf3cc16-4655-5e4c-b42d-8ff9e379e34e",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0533003-0eb7-5d47-84f4-69d02a9bbed7",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:333bea29-e16c-58b0-9ffe-19f410626848",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:158220e6-33aa-5304-93f6-39d41c07d944",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37d7e9ff-3781-5ddc-a003-1438519942c2",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2e40c97-7653-50eb-a888-78b992e2cf5c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3a925e2-6efb-5bb1-9075-0add8f7785b5",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df43ad7a-dee9-5ba0-92a6-8f9eb578774d",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9a685e4-6a1e-5659-abd6-5c54a146e6b4",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:557ea148-b44a-50d5-a820-a2e9a658dbcb",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70aa762c-8317-5921-9432-9d7eab4ec4ae",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f1d723e-fc50-56c8-bb97-972cb8fc5afe",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:273973be-9715-56b1-89e4-95b8d8f1613a",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aabd78d-13ee-57cd-8d6f-7b51af41b5dd",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2fdddd41-8cc8-5aa8-b649-61a60394a8c2",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa258041-2071-52fc-b763-dd3a1ba27d5e",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01d794a7-17e6-5c21-aca5-f7b7c5e9d00b",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38fa807e-6924-5cd1-9499-9bd0347a0204",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b608374-35b9-5280-b527-3635616902a9",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c8ad56e-680d-5f51-a4da-ac954f3f0de9",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b17624a-dce0-5bcd-9217-f1a7af2641fd",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1fcaa19-6dfb-57e6-ba43-9fc901025efa",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e41ece25-5ccf-589e-a913-7b37d3fc0e59",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29c88a99-4dbd-5389-b839-a18adb661bf7",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:087c8cdb-6c06-5fbe-985d-e182b06e7e1c",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e182fd2-b94c-530b-be81-a83cfeaad2ea",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cfc89fa3-361c-5fc1-834d-fd6b410568a2",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:886b59d2-7e52-550b-89e3-4556be7de479",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.sts.systests:cxf-services-sts-systests-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.sts.systests/cxf-services-sts-systests-osgi@3.5.9-tuxcare.5"
    }
  ]
}