{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:36ecc5af-ae6d-5684-a5fb-211ea9da849c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-storeconfig",
      "version": "9.0.90-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:a1483bef-6726-5c41-bec6-9c199c9fa47f",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76688af5-700c-583b-a8fb-53b9ae9c2668",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:32cee23b-6c2e-5209-aed7-c2b72c815164",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf4b68c4-e283-5430-8eb4-aabd7ec1d02a",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b25e915c-ef73-536e-8505-6b539abec3c6",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cbb2b2-eb5d-5225-8814-ebdfa47e19c9",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:221afde3-be6a-5738-9211-2fd27816148e",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08b6da42-c626-5a75-98cd-cf8f97ae33a6",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71348789-9acc-5d90-9833-077d3d91a322",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d4a1bab-dd17-505d-8523-dda66f29a2da",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24e1a319-95d6-5eda-b914-087919a67451",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dfa9fbf-85a7-50a2-985c-a2b793f397f2",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cec91744-aa3a-52de-a4ba-d1d9d457b50a",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7fd94d6-3ed2-5980-aaee-5db9cee249dd",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62633204-9881-5ae0-8245-c119d902f022",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fac557c6-e183-5e4a-80d4-a41c6de0be93",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2b42778-155d-584a-a46c-42888abb99ef",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b72ec0d-4649-51eb-9fed-5886bb57d804",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:363b707e-7d98-5436-9688-14151f2a2055",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7340b6f1-4164-5fd7-b390-22b45fb0c8c4",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:652c54ed-bc27-54aa-a1fb-715ae1e77956",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f04e9e71-8a9d-55d9-8bfe-7847823c4db0",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:66c4ddab-b477-5c30-a034-6b52368463be",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:511fc227-03fb-544b-9338-7f4da5d947e3",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:622b2db0-7578-59ce-8218-1479724d04eb",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a310cf2f-6d51-58bf-98c9-b163cddc73d7",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de963877-b4b8-5bb0-b2d4-83cd73913594",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d82f738-98ae-545f-a691-97b455b1de73",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:635f9ee9-00ab-5b76-ae77-b48247440595",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d84d7798-725c-541e-a8df-d09802deb7c2",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ee7be4f-ebfa-57a3-9803-b7a40fdbca84",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:80ab6f04-f24e-556d-85cf-b0dd59021095",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fa20b94d-b3be-5154-99f4-bfe7c837233d",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d531b5de-c3d6-5652-97a7-ce467ca520d1",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8b92bdd7-1ff4-59d3-8146-e196487f327c",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4801cd34-feb8-5f88-85d3-27c95dea3c73",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:386a308e-7a13-55e7-b3a6-d45ec1827f12",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03a377bb-3365-5a51-a6c2-3009bbadd35a",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b337f12e-a02a-51cc-b56e-e612f837276f",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0e45181-6111-5404-be92-a43f8f76f23d",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34487 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.90-tuxcare.7"
    }
  ]
}