{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:4b50bd7b-e64f-5f71-ab3e-1c3e6839873f",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-jasper-el",
      "version": "7.0.109-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c2246693-adfa-5ffd-9b89-c731ae1471bb",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a18d8bc-748a-5169-ab6f-137600fcddb1",
      "id": "CVE-2015-5174",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5174 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f4c9a63-0679-5108-ba8e-8fdb597be9bf",
      "id": "CVE-2015-5346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5346 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5a3e96e-334b-5ffe-a3d0-4208330d0f88",
      "id": "CVE-2016-0706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0706 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86e095c7-fbcb-53e3-bcdf-9c409d460874",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c92de453-4090-50a3-b225-c5db8a3b3452",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a75cd6ed-f766-5584-8e58-cda1f15ebb7f",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59086c25-5589-59e3-88b3-b01eac73034d",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a3268f-10c3-5128-8d3d-fb081961607b",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c515c98c-cf6d-5a07-b6b3-75f8ab1076a8",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7082ddc8-ef3f-5b47-81be-da4dbfc09012",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6816 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b20b78ef-f9d1-5d3a-9f45-9cacaf308791",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6817 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4bae9506-b513-511a-acae-879b1c2ae973",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acfe1d6e-d04f-5bc4-9af5-44ff25d5ffa8",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8747 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c25c9a1-6a8e-544c-9b1f-e9e27cd98408",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a02dcfd8-8a8c-5caf-ae8a-774f83c591de",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca8e83eb-2d30-5544-89c7-9d32aee6b15d",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d53d921-24a8-51ea-8b1f-92ae59492db2",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5650 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6c56340-d245-5e80-a8de-c76b208a238f",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:779daceb-0bd3-5f17-a96f-ac1ead261823",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:755d4d22-c8ff-57a8-9d33-79257d3e1d1f",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de0cbf50-1d5c-55ae-bca8-7f97480454c8",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7675 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f453073f-e1da-55f6-a243-7a239f137580",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ce8b1ee-1402-55dd-b80b-baf83e392c87",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1305 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:474c1390-13c5-5323-a7f6-d5145738fe99",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1336 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a294aef7-e831-55a6-8f19-23314b77848d",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8014 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd0ea77d-fa40-55e3-a5f5-828069435c54",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:98db256f-9bbb-5436-b24a-7d25697c69fa",
      "id": "CVE-2019-12418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-12418 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40de0e92-1bd7-549b-9fac-6b59e1551144",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3281767-e616-5e67-9fa6-92c79da9fe58",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0af17da2-655e-52be-b0c6-672b96580451",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6c893ad-6064-5530-8325-9d88e3b7f240",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ee95504-0089-5881-bbf4-8a7a29f49f9e",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52d74ef3-dd23-502f-ac9a-dbc1c097a8f6",
      "id": "CVE-2021-30639",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-30639 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65bebf47-46a6-515c-8b56-286025eb42f1",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4a6b811-fdb1-5033-8922-e80cefd49022",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-23181 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3a29143-92e4-556b-bba0-857ccc93d882",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c807d5-936b-5878-9eb4-fd29539dcc51",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de8e0f2e-5070-588b-87d4-154adb9dc180",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4362f37d-5685-54f6-951a-2849ecd2b202",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38286 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb92cf62-8048-579b-a581-c75047e3b24f",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ea799b9d-3b79-5e98-b240-5e868abd1006",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:85ba6d4e-2e1f-58a6-af48-c7cced55693d",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2ceee001-dcb8-54ee-ad19-56c1f940171b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:510d92ca-e48b-5506-b562-e847cd1e0fd9",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:449945c1-798f-5e76-a601-e1a3b21a0be9",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e2a776a-853d-59c5-a822-bc39de1ecbdf",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c1ab6d4-f00a-5823-83f0-99bf43bda285",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b50e355e-faa4-5f05-9060-5f50275edd22",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29145 does not affect version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el. The official CVE record (https://www.cve.org/CVERecord?id=CVE-2026-29145) limits the affected versions to Apache Tomcat 9.0.13\u20139.0.115, 10.1.0-M7\u201310.1.52, and 11.0.0-M1\u201311.0.18. Version 7.0.109 is not within any of these ranges"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:352029b1-0454-552b-8eb1-9c63f3e471a6",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a076e033-937f-57e9-867f-4c7c2b172f2a",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 7.0.109-tuxcare.1 of org.apache.tomcat:tomcat-jasper-el."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-jasper-el@7.0.109-tuxcare.1"
    }
  ]
}