{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:a6dede79-3d8b-5ff7-b7d5-8aecc4a2c5c3",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "6.1.7-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:c8704fc5-da25-5caa-8a34-efbb8b954ce5",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:549e0fbd-a8cc-5d93-82ce-f58f8dc535a6",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1b69e8ff-6365-53b9-a6fb-4513aed7f454",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38819 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4cc0a84c-82a8-5b2d-b61c-116f04410fa2",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38820 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df24b406-d335-5b60-998d-0c394b2d2876",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdbabf2b-c094-51ec-a3ef-d461710479f1",
      "id": "CVE-2025-41234",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41234 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:64bba97b-4e64-504b-b128-998f5ddd6039",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:83f99c9d-682b-5a46-a8d1-480d141225fe",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44028d11-78b1-5c0f-a446-649e88b69ec9",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:627696e8-19ec-583c-b997-878ba422d0a0",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22735 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8212cd0-ef8c-55f0-915e-b6b2f0428846",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ee0507df-3846-5385-9bc3-58b9ac10da4a",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb969fa5-d72d-5253-9f5c-ec6d26401fa1",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5d32ea0b-1421-5042-b156-e937648680a5",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22745 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6520d838-5520-5b31-a35b-d0c398eba80b",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75a76b30-a207-563f-8b41-fdbb1ba1da2b",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:610c2b5e-c53d-59f8-964e-c5815463f413",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41840 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:55256e80-e650-5191-86c6-c8d0c714fe73",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:207be75c-33e7-5248-82eb-532ed04ca48b",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a323c169-923e-5a61-949a-268a2189595c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0e5a4e78-d339-594c-ae50-f3a1a28efb45",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b642ac7-cf11-5db3-ae4f-ddfa4aca0b67",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78cd19c8-04fa-5ce0-8ca7-3b72e093bb2c",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b03a083-8000-5ebf-88d6-50a5bed1cec0",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:48460d67-24c6-59d1-a957-69582ec9e7c4",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:934d2a26-a9d5-593a-ba1d-48c7995e3a4e",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d98728f7-df21-5b3d-9f66-f9f7420df45e",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7b2e3fa-091b-509e-9e53-f79ed3f650d0",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:44967ef4-4276-5551-939b-6cd42b056e28",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 6.1.7-tuxcare.1 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@6.1.7-tuxcare.1"
    }
  ]
}