{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:dafe6fef-4bde-589d-923d-1a4e4de9175e",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-rt-rs-service-description-common-openapi",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:6d9dcef5-c958-56ad-819e-ac246d6787ca",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8314c232-f5ce-547d-8744-acea452a1a00",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06380abc-44e8-5684-bc52-469c17166993",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f61e6770-8fbf-5f3b-87aa-4b3f1e36010b",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ed3121d-af1d-5a9d-83ec-219a5c026a08",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e456aeb3-033a-54b5-b340-3edcc2577c79",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3a91b2b-ee45-5c94-9c79-b342fe9b183c",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec3d10ea-bbd1-505d-b060-c4c9cf7ea644",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70be4a7b-4a18-5559-8f53-6a21a11d2a3d",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a9f52c58-c603-526a-ad87-539e94b5b8f0",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:daa38562-fa6d-5a19-bced-d429d862e583",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8975e68e-170b-5d22-8021-7a79e1279606",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07bb744e-a993-5a73-9504-7b3cae7ce892",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f641a946-8573-502c-9542-aa8e89f045db",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5aaf352-4712-5e2d-84a9-d3dcc7f2d91d",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41d6239c-c7b7-5895-afe5-3f72de5ec239",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8476fed-a917-5358-8d46-e07d2b11e8d3",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-rt-rs-service-description-common-openapi 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:beb9112d-f09d-58c6-b53e-0f41651f3b8e",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1477fc88-a6ea-5893-99d3-c3c2a1534a97",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2dce25f-bdb9-50e9-8fbb-b8e3385a557c",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5e664a7b-ca29-5fb2-b34d-c34e09271061",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3cfdd4d6-ca86-52a5-a73e-e32d5d2278cf",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14958c13-d660-5776-96a5-b63aee7d64c3",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c55bc09d-5048-5c2c-b221-6d5c43bd7b96",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fc97a19f-ae27-5652-96d5-19b21eb10e38",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59119c8a-abd2-5656-b864-daa82c144d52",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-rt-rs-service-description-common-openapi 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08c9f29c-b6d3-5598-bd74-1d806982f131",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4ea6c01-a4eb-5f64-a1de-4f59c900b6fb",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1c339de-0346-516e-991e-7ed31aac70cd",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b39c30b-d060-5784-981e-3363a5b67fac",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-rt-rs-service-description-common-openapi 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec352581-5e56-53af-9565-5f84751c0ffe",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ecc963-55ca-5e31-bd31-3707fa96cee6",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c34526c-6837-5291-b117-0625e60ee6d5",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c392a7-8aa1-5dca-85c4-a03f4b456dab",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-rt-rs-service-description-common-openapi."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-rt-rs-service-description-common-openapi@3.5.9-tuxcare.5"
    }
  ]
}