{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d2220330-b4fb-582e-a734-05313b38fefb",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf.systests",
      "name": "cxf-microprofile-tck",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b380a7c8-e71a-53f5-b3ca-6cc6e75c755e",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4035f0a0-e33b-566d-9746-c9477180fa53",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:929c1367-8ffa-54e8-b252-03c3aa9486f6",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:025b839b-bc22-52ea-a4f2-7ec92fe2bc4b",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2126b72a-c442-5663-9cad-1a18ab1a30d3",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd406eed-a985-57d9-8dd9-307e092414ef",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66ef76ae-918a-5c0d-8678-ede65f69ce08",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c799302a-deea-5285-9871-4be2bfe932d3",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5c5b878-07f1-5852-a3e0-8f9f2b3f794b",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa656916-0359-56f7-be89-46186bd7cec2",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2db5875-fed8-58a3-ab64-a0019fa47af9",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9442f73-ecae-577e-a76d-0a9e790a75c7",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9d37e63-ca96-5774-b92b-8d9dbcd1e372",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9eee018d-a11a-5c3a-a4f3-f61a808ad952",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10601fee-fab3-5aea-b881-9d3947471430",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc64e26-7c4e-55b0-9941-60fe9628f393",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea76aa16-246a-5e2b-9f4a-b46c203ee01c",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c25d9d90-f383-563b-91b8-2ce975f997b5",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae96c886-9e1b-525b-9003-6077cfa7f4b5",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d051136-96e7-5277-a723-a4dda69da5a5",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:72911eff-a946-5da9-94f0-f741f93e7f3c",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f46ad73f-09e6-5734-845d-31d1aec8664f",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0adc2ab0-d2d3-52ae-9aee-f87606ac093a",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3fabcefd-65e3-5a46-8c90-288849ae5f60",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3e6aea7d-c791-55a9-834e-75d8eee213a9",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7bf230d-3b71-51d8-9691-17baeb0dbcce",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.systests:cxf-microprofile-tck 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce5693c9-bae3-50b0-b4f2-eea8392baa31",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f46f37da-094f-5fc5-b303-c0da8cbb9690",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf.systests:cxf-microprofile-tck 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41c72987-ea8a-5ed5-bf8a-032e3695057a",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aa035fd-44a1-52b5-85a8-a208b0fc796e",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.systests:cxf-microprofile-tck 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5342e284-f16c-50bf-a476-1fa471be3341",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99b8215d-1c60-51fb-b2ce-f49024dcbba5",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf.systests:cxf-microprofile-tck."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.systests/cxf-microprofile-tck@3.5.11-tuxcare.7"
    }
  ]
}