{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:6a3c6078-14a5-579a-a240-f15815a3b7ff",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-jdbc",
      "version": "2.4.6-tuxcare.4",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:d3c83ed1-e0b2-5678-afaf-bb1827270cf2",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6a6b9ec-a174-5de9-b4f1-595639213d9f",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74ff148c-4048-535e-8b66-567f6ace469c",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b88a763-5dbd-565c-8394-66329fcbb97f",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c6f589a-ad5a-5708-b057-69a1b9ac396d",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9852642e-b6f2-5939-abfe-d6b0967c0edf",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dacd5751-51cc-5db5-ba12-5ce05b7b9605",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d7b06c43-b7e4-5c84-94c6-6cb2755ba15a",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:18d008c6-6d2e-5ab2-8992-db9531afe9de",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5a2fa4c-6374-5337-9dec-765d321ae3f7",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40973 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:50cc2f03-f13e-561e-96fd-3bcae060590c",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40974 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e94d1a59-79df-575e-b141-3900299ccda8",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:286e3ece-f8da-51e0-8e0a-90b6252be6e8",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3284fa4f-f79c-5fb4-bc83-39451be6611b",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b92c89b-0c74-5635-b6b2-4ad29b27027a",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.4 of org.springframework.boot:spring-boot-starter-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.4.6-tuxcare.4"
    }
  ]
}