{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:54cee63c-1688-54c5-85c4-eda37d31711a",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5",
      "type": "library",
      "group": "org.apache.cxf.services.xkms",
      "name": "cxf-services-xkms-service",
      "version": "3.5.9-tuxcare.5",
      "purl": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:dd7c11fe-6294-5e74-85e4-ac83d63ccec0",
      "id": "CVE-2005-4838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2005-4838 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9e91fb9-fb5a-51fb-9f47-1c8806582886",
      "id": "CVE-2006-7196",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2006-7196 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebfed0cc-82b8-5649-a36a-b2f5abfad272",
      "id": "CVE-2007-1358",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-1358 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:95a848bb-f2d3-5cd4-be32-06411de07460",
      "id": "CVE-2007-2449",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2007-2449 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9acca87-61ad-5e66-9b9c-0b03853104f6",
      "id": "CVE-2008-0128",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2008-0128 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f2bf42-67c7-527a-9d29-e7bdeccea301",
      "id": "CVE-2009-2696",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2009-2696 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f74db1b0-0258-5af3-ad70-9575099be351",
      "id": "CVE-2010-1151",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-1151 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f564a25d-efdc-573c-af34-25662d39fe84",
      "id": "CVE-2013-2185",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-2185 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2197cd72-025c-545e-bc5c-b01a2b253e0f",
      "id": "CVE-2013-4286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4286 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:371ba371-9cfc-5349-a538-f18d179c7944",
      "id": "CVE-2013-4322",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4322 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd374847-6631-5177-aa5a-c2f657200224",
      "id": "CVE-2013-4444",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4444 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:25d4923b-c6a2-5d9e-8f23-a056e7cd1bdf",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a8b12af0-d653-5683-b60a-f227a93e4881",
      "id": "CVE-2013-6357",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-6357 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd2cf894-6adc-5091-868f-39238e07cc8c",
      "id": "CVE-2014-0075",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0075 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:57f6cb9e-7415-5cdf-9417-e11ebd4b1acc",
      "id": "CVE-2014-0096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0096 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e777374c-9208-56c2-953d-1ed4b13121ba",
      "id": "CVE-2014-0099",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0099 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7bfe473b-e377-50dd-8d47-21818b8baaa6",
      "id": "CVE-2014-0119",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2014-0119 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-service 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ae3bbf1-1f33-5aa9-b70f-2dd35b341787",
      "id": "CVE-2014-0219",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-0219 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a4ee87-c172-5ba1-8820-9a6d64902544",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:533ae30b-0142-5954-88f8-c06212ddc6be",
      "id": "CVE-2016-8750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8750 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb6dc8b7-f086-59db-a5ec-ac56175e8b8c",
      "id": "CVE-2018-11786",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11786 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a83a35-6106-5125-98f1-9cd924e5a730",
      "id": "CVE-2018-11788",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11788 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70f3efa7-7892-53b2-b324-f450bfcdc50a",
      "id": "CVE-2019-0191",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0191 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87a1f94d-5463-5217-96b8-3ce66a74d463",
      "id": "CVE-2019-0226",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0226 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:599a8ec8-1acd-5e31-8552-ba83fec5bea7",
      "id": "CVE-2020-11980",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11980 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2ba9dae-c340-5f39-a212-5f509d233df3",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-service 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59939cf7-ee44-5ff0-9eb3-62aeff00d1d3",
      "id": "CVE-2021-41766",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-41766 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bcd19fbd-e8b9-58cb-938b-852fe7265af7",
      "id": "CVE-2022-22932",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22932 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2aff9ec2-0e64-5c55-84cf-e4a5290d3bc5",
      "id": "CVE-2022-40145",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-40145 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d418aae7-9655-52ed-86c3-39165ef14dbd",
      "id": "CVE-2025-15104",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2025-15104 is a false positive for org.apache.cxf.services.xkms:cxf-services-xkms-service 3.5.9-tuxcare.5."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:107f3937-3ec1-57b4-aba6-7ee5c2a92c5c",
      "id": "CVE-2025-23184",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-23184 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7a54e67-0997-56ae-a4e0-dc95843f7a7e",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-24813 affects version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b2b8d0d7-d730-53b0-af91-d42f14d5bbe3",
      "id": "CVE-2025-48795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48795 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:08611f13-c297-5913-a9e7-580f9a647b6b",
      "id": "CVE-2025-48913",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48913 is fixed in version 3.5.9-tuxcare.5 of org.apache.cxf.services.xkms:cxf-services-xkms-service."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.cxf.services.xkms/cxf-services-xkms-service@3.5.9-tuxcare.5"
    }
  ]
}