{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:64f835a0-92e5-51f5-83a1-b25a31f529dc",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf",
      "name": "cxf-runtime-javascript",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:3459a32f-3c7e-59a9-aa89-6e9103e35d06",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d0cd2a7a-7556-5147-9867-9f47b8c2cbc5",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c569899-d03d-5ff7-ac5a-9e606efcfd41",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e1a42873-1589-579c-a01c-3090005a77a5",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94827883-692c-5738-9c06-f78093973524",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2537f153-c9d8-5256-bf52-d036ccdb46a0",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e660a88d-336a-5933-93b5-a999821f8ee4",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cdeaf446-8d22-5a0b-a4b9-ef899ccbfbac",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7eee79f7-bbfe-5599-985d-d960244927ee",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b768532-8751-54c3-9dd8-957fd0ab4d41",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bfa7e548-f0cc-5fa4-bc19-67fce8bab001",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b09b2a7-7f5b-50d3-85cf-b39f94fc5c3c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a860b1cb-5d90-5cc5-a859-a1ca8c39853e",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96514757-8067-51f2-afed-4e7740b456c1",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d30aa61f-1910-5961-8caa-715ba02e6af3",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4df53519-e68d-5afd-9fcf-7c15e33010fe",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b82fa53-bbd2-5a57-88d2-615b81881080",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf:cxf-runtime-javascript 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:578fb51d-d5fc-5c98-9e69-e0b168dd8e67",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4580e9c0-86dd-5d6e-9e47-b02bd1516fa5",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23f9cd77-99d2-5b65-ad1c-4542a966c4b8",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f8b7660-6c30-55c1-8597-2f27762c85f8",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07e9a7bd-d26a-5229-a6b8-91df2c70408d",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:30becb8c-c814-57bc-a680-27707b0c3703",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c75f0455-f042-5266-8881-8710f247d989",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dd938c5-c979-50f7-a67f-57507968c92c",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab208f0f-302d-54f0-ad31-4f86e5698103",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf:cxf-runtime-javascript 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35abb438-4455-5f04-96d4-eac56ae8e7fe",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed51cd75-ed75-512d-8e99-0a7890b38d7b",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f46797ed-433e-5e93-91c7-a6c6995a3a77",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39f3b836-caf0-54f2-873d-0a11a34476dc",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf:cxf-runtime-javascript 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59aefc6a-480b-5247-990c-f7ac63258c43",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d214af98-676a-5124-95b3-6c691c33315a",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3127795d-033f-5ad5-92d2-b72018a0fe0a",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42581782-8706-54dd-a020-392fa69a0d3f",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf:cxf-runtime-javascript."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf/cxf-runtime-javascript@3.5.9-tuxcare.5"
    }
  ]
}