{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:250ed271-8ca1-50bc-b6bf-6027b8da2fb9",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "6.0.23-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8a11f59a-02ef-5274-8e03-57346cd298ce",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38816 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d5903c9-fe21-52ec-b474-4bba23201b25",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc4abc2a-a935-5605-8891-29c8658e503c",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7cfa52db-c821-506c-b598-4c5fd5cb34ff",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36769ebd-ab5a-5b1e-812f-9168554c54f3",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41234 is fixed in version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91a4137b-9b2d-5a28-aa3c-f6b3ada4ca2d",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b77e4244-b923-5122-a528-c64385cb4470",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47a5b1f5-349e-5f2b-83ec-7bb3dff73046",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05ef8f59-be5b-5a01-9c18-ac8e130d614b",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8e609dc-1cdb-51da-97fc-ebb14df7bfda",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91d22287-056f-5609-a73f-be56aeb94ecb",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e35e39ba-dc93-5c3e-ba7c-0565fba8ff34",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:984c91ec-b866-51e0-9574-30792fb79d67",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.0.23-tuxcare.2 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@6.0.23-tuxcare.2"
    }
  ]
}