{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:d22f252e-dea0-5c23-869d-b3b26c6ec565",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-util-scan",
      "version": "9.0.90-tuxcare.7",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6f22ffa3-d2ac-5368-b4be-0344d9360db6",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e67794af-ef03-5000-9902-e35b470ae687",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d3f27a88-f943-5eaa-97d4-ead93f8a9bc5",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan. Fix for CVE-202-13943 for this version has been already backported by the original developers, so brunch 9.0.90 is not vulnerable"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24061415-a9ec-5ff8-b2b4-3e3ed8dcd517",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1e0f5d3-3236-5430-8d72-dcc6eaf9dedd",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a4a8daf-f46b-5c19-a3f2-e28567638390",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d28244cb-f8ee-56a6-a079-b1a5a3d26463",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ad8b595-11de-53c5-8e5b-f9da35dc3d1b",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd5c73b5-da50-5b63-9a80-585330b847d1",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a927690e-d3b6-5a0d-b6b2-8e5839599c3a",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07ffcc0b-d72e-57e4-a40a-411a232a73c8",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fde1abfe-e35d-5f65-aa64-0716374fe487",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:011c81e4-36c5-5dd3-a33b-99fd836c3384",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b6e60b2-b0f5-5369-87af-27db1093bfd6",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4221df1-8e67-5cc4-8dc3-8081857e1f78",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473f8854-6f9b-5e4f-afb1-9abfdc19fbc0",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b401dd0f-7a55-53fb-a70f-6f7c6fea6776",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75fb296f-cdd6-5344-9479-0a664eb88101",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54618c53-74ab-5a32-9810-15d080a8bbb8",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e96c646-406d-576f-9796-6f4b8767fc5a",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eaeda57-69fd-50ea-8a6d-94cd1d081086",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56759e37-e0c6-54cd-bec5-84392c0f19d2",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e5c9ca8-1ee9-5e66-8beb-2069f1bea3eb",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2bb23b-0ee9-58ee-9265-3a0679d2f099",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c1f2d2d-6cde-57f1-84c5-7e1d6adb1b4e",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2ce9c3e-b3e5-5ad8-a90f-c85340422517",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0a34851-c94b-55b8-83e0-8f55db6d8974",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63b4e57f-e306-5a44-955a-c7167b16aaf8",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bda2c7c3-85f0-5680-8b81-3ccdb118b9a4",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f88747c-1e54-59bb-9a77-2ce2cfb6dc27",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:326af2e0-6f50-5e29-8533-170c7dfc802b",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4466f89-f679-5705-b6f7-217a66c7fbdd",
      "id": "CVE-2026-24734",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24734 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2029492-aa5f-55c7-bf24-0595c0a60104",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84cbf5af-1f62-5922-8611-33807bc87420",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65162d28-529f-5772-866b-a290ca5c011e",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29145 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a849fcb3-f575-5347-8a8c-72beef244cfa",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:463f5097-5c01-58b6-8786-9c5d38fcc949",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6e5e9407-d9db-5dae-b0b3-4caac98af57f",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34483 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dae5c3dc-c8de-51d5-9938-6a3dd75ed4d0",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0c814a0-41b0-5ca5-adbf-a93f34f58e32",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-34487 is fixed in version 9.0.90-tuxcare.7 of org.apache.tomcat:tomcat-util-scan."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-util-scan@9.0.90-tuxcare.7"
    }
  ]
}