{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:105580ef-359b-5597-9523-d8a29a0676c6",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-instrument-tomcat",
      "version": "4.0.0.RELEASE-tuxcare.3",
      "purl": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:9a651791-875f-5368-ae0f-def39691b245",
      "id": "CVE-2014-0054",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-0054 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30836dd5-bc8a-5aff-81cd-a1cb780e1470",
      "id": "CVE-2014-0225",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-0225 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe32ddf7-eb4f-523e-a723-a06144641802",
      "id": "CVE-2014-1904",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-1904 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71c347f4-82e4-5462-85ab-f029daa98ad8",
      "id": "CVE-2014-3578",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-3578 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:014bee44-2aa3-5008-9be9-19f59b6d0194",
      "id": "CVE-2014-3625",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2014-3625 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d686844-0ade-5580-997a-e1fce4bbd540",
      "id": "CVE-2015-3192",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-3192 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f4e30b3d-941b-5bf0-aa7b-8d43eb44f062",
      "id": "CVE-2015-5211",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2015-5211 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07dd8f8e-677b-590b-8bb6-de69958a4141",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db63ba23-b94f-54b4-be32-b2a0b198ece9",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-5007 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0e7c169-1de4-50b9-b0ae-75e657ee9820",
      "id": "CVE-2016-9878",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2016-9878 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f13e314-fc53-5ca9-b8c6-59dae79f10e4",
      "id": "CVE-2018-11039",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-11039 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:accd97f4-2fc3-5996-b7d7-7f573bfdf121",
      "id": "CVE-2018-11040",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11040 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca8cde5-76a4-5fd0-9a83-9aeef64fb655",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2018-1257 is a false positive for org.springframework:spring-instrument-tomcat 4.0.0.RELEASE-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb191a05-316e-59a1-bcd5-0378d02110e1",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1270 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7653da3e-7a7c-5770-89b6-aadcdbb18b27",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:686796a7-6f1f-54ba-bd34-f4d1b3cfabe0",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a3391a-9803-5381-beed-e6ac85240cf9",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1275 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:786b72ac-1484-5d5a-b119-d13bd88bd0dc",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945338c1-12ea-597d-ab04-49feb971373c",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6258a49-40a8-5e5f-8c84-7a5c97319409",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb73d7d9-f6af-50cc-8a23-d26a639ef0c9",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:122fc5ee-553f-53cd-a8e3-5ece3842d023",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c220ea99-ea09-5e21-9755-cdfb13fb8996",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d755a37-a6ba-5650-9e60-4e27dd303af6",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33a442e5-4065-5c29-9c28-6c49c8191498",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ffa730c-7280-5918-8327-483f405922b1",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35b63dcc-a052-5eca-9fbe-5c206e2867f8",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8771daa-2dad-5e8b-9948-a0fec1da2a40",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0a4ba49-5615-502c-8149-85627021c52e",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9aa330b9-9522-55e3-bd3c-b047eddd4551",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:650af72b-9477-5945-b639-f3b35697b84b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6f5916db-4fcf-5f1a-99bf-24b8eab9bf51",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bf3a9d6-4484-5392-8857-64baa43c8b6f",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02bf6a69-e81c-567f-8bde-52ce2c738b50",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbbd5d40-9331-5e44-a7ba-6830d2e8b890",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bde567a5-0110-59f0-9076-13a4ba46e50d",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:acb04821-6925-5538-b5f3-1a319865ac01",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4c511af-8407-5e3e-ae09-2395124ac9b5",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:487d4195-d101-5cab-b129-029b2d0987de",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:afcc00fe-2c78-5d4e-a199-0e343155abb4",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8a60f2f-1586-52c5-beb9-6bb0506541af",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.0.0.RELEASE-tuxcare.3 of org.springframework:spring-instrument-tomcat."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument-tomcat@4.0.0.RELEASE-tuxcare.3"
    }
  ]
}