{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:365efe6f-a0fd-52aa-9c83-7f38d58b9d35",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-oxm",
      "version": "4.2.9.RELEASE-tuxcare.2",
      "purl": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:37fb6560-ebbb-57e0-bc4b-e38e07c6b92c",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37cb8326-d418-54fc-8073-b64969ad047b",
      "id": "CVE-2016-5007",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5007 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:008658a4-79fd-5c53-a492-5d71315f2f4e",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1257 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:41fcaff2-f078-503b-afdd-9c6f17a9f4a2",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1270 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db37eeba-7799-557a-87fb-e4fddad3bf13",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1271 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22c5d9cc-e5e0-5526-984c-5fc9bdf11930",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1272 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d99dbc6f-f205-5af5-b095-c5afd7dd19de",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05f07d43-7b79-55ef-9075-e058c4cf070c",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-15756 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f4d81b0-712b-5073-b2d6-76fd2b4f55bd",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5421 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a9438c6-1ed8-573b-8fba-da93095a9a84",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ad9c4b21-9d1c-596a-85be-30796c58e792",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8210d7d-a401-5b1c-aebe-9b34f6415db2",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63993adc-88cb-5ba8-988b-5a75f00d5938",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f114c794-31c6-5362-85e5-8f99b36140bc",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cda7d2b3-9550-5792-a1a7-a80e4261de93",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2e2853c-ddc0-5497-8230-13d49230928b",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8112fe82-1135-5a86-8ab7-f07e226efb6b",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478f6891-b092-534d-a511-6b452996d93f",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dbe6d90a-daaf-5273-8f71-5700210966bb",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c8f927e-bdd1-5146-9ad5-9bc3427bdf23",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7044242f-f1c7-5f95-b31c-b727de03707b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3e7075d-0ea4-5b83-9196-f0ebe74d1729",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f40c763e-0c3d-564e-83bf-49c3f62e0051",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a32593f-e82d-5301-8b9c-8736d02b9a93",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a5256f4-6b89-55cb-bcaa-b7175cba0b4e",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69bacf60-8ffa-52b7-8504-639821f2e9f0",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22086608-ce87-54a9-af95-9801ae3cbb10",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d12d9bd-41e6-5246-9370-695aa1ee54a0",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fac86bba-98c9-5077-9798-2d6d84a7b722",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46f3fa81-ba0c-5e1d-8e75-94d3b6f644f8",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b63d9f5-d138-513d-a0d9-ae445d2b3e87",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:763501e3-7ec3-5093-8c30-3d840e1fbad5",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34279ad8-d2d6-56d0-827a-437840aef01c",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c845f07-04e3-58f4-975f-f7edafd2b4a3",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41845 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54d98f35-d639-572e-bf28-5cc3b983207d",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baad8060-ba5f-5647-b8c2-d4cc7b65bcc4",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baca4abf-4504-5085-9ceb-7a6fd3ef3b37",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4642375f-141a-57a5-8b2d-f273bb7a73f4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6174e07e-3b8e-57c8-befe-0f457b7fd287",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:45e02332-c4bd-54d3-a8b8-eb3eae4beb0c",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7453ca86-6d81-58de-8869-bad4d0a52a2f",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8111db7e-e4c5-5b6f-9005-434b71570a80",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.2.9.RELEASE-tuxcare.2 of org.springframework:spring-oxm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-oxm@4.2.9.RELEASE-tuxcare.2"
    }
  ]
}