{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:defac316-7bcf-5934-b838-4e60b7fd4abc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-osgi",
      "version": "3.5.11-tuxcare.7",
      "purl": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:b6d9861d-b067-5593-835f-9ecbeeec201a",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:178bcc37-1940-5235-b473-b8c3e98210d5",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8213c49-7d64-5673-9f6d-d832a685bd63",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b3d1d9b-4185-5e99-b80e-d6d9d8d118f4",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67985b44-fe48-5768-a468-d1f9732d64d1",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f75f16bb-a51c-5ebc-80eb-b7a0e27aa9a1",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0aaecd34-2031-5078-96ce-c14ad178d8d4",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4aa5cab7-e801-5e6d-848b-369bb98ffc3d",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:103c6907-ae07-50d0-83a6-2305f1769760",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c1a9d10e-d5a3-522b-b18a-fce66ffd92b2",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c65b3e2-55cf-512b-a3e3-fac33e897091",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:241e6346-02d5-5c55-a557-b69eeb77cd54",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:10cc2fb2-7e89-5556-9e6a-673397ea3ad1",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:261c3e63-004f-56db-86df-350a41b8ccaa",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d666a6d3-cdf1-50ae-b95f-92291f344e55",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0d82b92e-1e1e-5c20-acba-e337e4d68336",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2076b56b-90d7-520b-bbd7-f915571e700a",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0119 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94fcf8ee-de64-58f9-aebf-1b162dcba26e",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8520ac4e-7793-52ab-aac5-38887efd7213",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcff0ca3-0672-53dc-8c01-ceb8d7f608ec",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33458b69-6b82-5a59-bda9-598a6f629509",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa3df80f-eef0-5781-8646-2057eed79d35",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b157ad14-fa3a-54d3-893a-009f6f609d08",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d6b8980-5944-5376-92a9-c538e1c9cdeb",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4e706fe-96f9-561d-a121-d7949d0c28de",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dc211b1-e45c-50e2-ab58-071f011e6738",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-osgi 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4fa50910-ceb0-5c0d-a8aa-a309d95e9cf0",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6771a6d-791b-54b4-be84-c8b25ce90537",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-22932 is a false positive for org.apache.cxf:cxf-osgi 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1400b5e-13cb-57f2-a4d5-85a611294f46",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57fd6857-40e3-5cf1-a777-8094bc07bd23",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-osgi 3.5.11-tuxcare.7."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d1324c3-2ac7-5713-94c2-e5bbdc7ee162",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d740ce42-d8c9-56ee-80a8-4f52c30c6232",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.11-tuxcare.7 of org.apache.cxf:cxf-osgi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-osgi@3.5.11-tuxcare.7"
    }
  ]
}