{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:005c7938-5bfc-5c45-a636-d4091c705283",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.services",
      "name": "cxf-services",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:05191f8c-4bd0-5f4f-94d3-36c090e959e8",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:879d4be5-5f2b-5b81-a188-b311d8abb421",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b9cc61f3-8d9f-5bef-9d18-5fc85a6b81e4",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:484eb1a2-e5b8-5fcc-8632-c51f933ab3a2",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9bedd6a-299c-50c1-9f60-189feadef0f0",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15e70422-11a1-5c59-9734-cf40d5d2ea26",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:976c9682-02fd-5c22-b032-93b1f28678d3",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eccecac5-bc72-5f6e-bd63-b8144daeab72",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c03939a7-b072-5145-9caf-ac740f57897d",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09d16c24-448c-5412-8f42-11b4e6a2113c",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de1a0d85-1af8-57a0-93b3-28f931ec1c35",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6703dacc-41dd-58a5-833f-2b192dd94e8b",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4885c7bb-4a9d-5595-b07b-e92be03607ac",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b0b30ee0-0f82-5897-8f10-4d68c9aa459b",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02fcee1-3ec7-5526-af7f-40a4ce82f7c3",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:050f56eb-8fa6-58bc-b323-5da09cce7c2b",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87db8482-1883-5595-96b6-81b40ec99198",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services:cxf-services 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:21d1fc70-d0f7-544c-93b9-8bd3a42ef4a8",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68487a5a-9b10-5693-bd19-c75b8195728d",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81692f7c-e042-59cf-a053-ee7a3567ba8d",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d39ce7c-59fe-5f8e-b6da-f1fed7b5f1f4",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17c72f91-7e60-5ad2-88ee-ca17fbe02669",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6803e67-e3a4-518d-b17d-ca785386c458",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a96fc402-0e80-5e20-b2b2-a6a6ec78d44a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a714f3b-a0b3-5379-aaf8-78ea2d2339e3",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afbb5cc5-17a6-5d1e-a2cd-720c6e867321",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services:cxf-services 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd3b1b31-1534-5fe9-8aaa-5e7385ae9bf9",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ede1579-c4ea-543e-9f20-35c0d42e14a3",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d74aae2c-19a3-5b60-825f-4957572ef5b0",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12dd8d8a-55c9-55e6-8c61-8c91d471767c",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services:cxf-services 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b5366f43-f58f-5a50-b581-6aca8934aa10",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d7f5c41-91ee-5353-bdd3-ae70ae2b8191",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca60f3f-b88c-52b1-91aa-cad8bccae2e6",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c126b775-fbef-5ddc-9587-55b2a2a53589",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services:cxf-services."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services/cxf-services@3.5.9-tuxcare.5"
    }
  ]
}