{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1cf68b2d-502a-5669-bc64-66c633eded18",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-maven-plugins",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:39570b0e-5bde-5601-a4ae-6431ab7b88f4",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1d1bf3e-27d0-5e36-ad56-9c5055dc4397",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:88adce47-68bf-575c-a2c1-753851be346b",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9efbbda1-01c6-58fe-a3b8-21c7a0efa7b0",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:135eb3fe-8e9b-53a2-a484-9c5ff7abc6c0",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3aace1-0339-5c72-aaf7-594628f9065c",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc3817d4-c42e-53b7-ac23-12831fc7878f",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6621b28a-220c-5019-bb74-62546694ecfa",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01a4cc5f-7b21-5ffa-b288-fe50737fc315",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca72cf4a-c5fb-51e1-901a-812fb08633ae",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67b93c7b-0a96-5eed-9331-4488174cabea",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af499f7c-48e7-520d-804b-106e9308e9e9",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:593d430c-e2ca-5f98-837d-69a809168c8c",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05a129e1-f8e0-552e-a6d1-3c297d65b8b8",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c46a7041-ce4e-5c3a-8aea-92ecf50d6d4f",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d86b447b-72f9-5169-9120-a416fb004ffa",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e57f06c9-278d-5216-9af1-1d19617a190a",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf718f7b-22c6-520a-b387-518fffda10dc",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95b64d7b-e436-5be8-be8f-ddddf5d82f99",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6dfe122-2aa8-573b-9a10-8438edfde93f",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29e7a9f4-033d-5eef-8699-60422a96eb0e",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d92dee31-de35-5e86-bd3a-1e526c7eacfe",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:446756d8-d50e-5cec-a644-025b310347f0",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b444f878-26d2-57e4-a640-d19f04eeac5a",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d0efe44-4f44-577c-bb7b-02460491372e",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6ffccc0-7bcb-5e3f-83cc-da93cb5e9a79",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-maven-plugins 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:47a08bb9-c258-5da7-b1b2-28c9c0b1e349",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aea07133-6329-5e25-a0b5-11d96c898144",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-maven-plugins 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1faeeb7-cbc1-56ff-be58-bd2b19aa4ed5",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfdbf759-339e-5335-a945-c41983e81463",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-maven-plugins 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:493d5066-c34a-5fb7-ad14-0028eee68a7c",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:767d4188-92cf-5eea-ae9d-7165fa3f832d",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-maven-plugins."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-maven-plugins@3.5.11-tuxcare.7"
    }
  ]
}