{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ef1c45b6-bde7-5eee-9ec8-41f1f7586aa5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat.embed",
      "name": "tomcat-embed-core",
      "version": "8.5.100.tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:5d48ebb5-57e5-5478-9f1f-5e23dbd1020a",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-0762 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2016-0762 timing attack vulnerability has been mitigated in this Apache Tomcat 8.5.100 repository. The fix adds password processing even when usernames don't exist, preventing timing-based user enumeration attacks in basic authentication."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7aae46eb-6690-5c74-9b59-1ef0c7cbdc7c",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07a148a7-a0a3-5799-a01e-49c48de7bed6",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22e262b9-17b5-5e75-b873-681442f8dd48",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:940cecab-75d4-57e2-95c0-ff42db992914",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6796 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2016-6796 is NOT present in this target. The target repository is Apache Tomcat 8.5.100-tuxcare.10, which is significantly higher than the affected version range (8.5.0 to 8.5.4). The security fix that prevents SecurityManager bypass via JSP Servlet configuration manipulation is present in the code at JspServlet.java lines 92-96."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:162ee885-c97e-5de5-a7b9-dedc37ae0d74",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6797 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2016-6797 has been fixed in this repository. The vulnerability allowed web applications to access any global JNDI resource without explicit ResourceLink configuration. The fix was introduced in commit d6b5600afe (August 22, 2016) and implements an allowlist-based access control mechanism in ResourceLinkFactory."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40795497-8452-508b-a7e0-f5dc8c6508c8",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6816 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Version 8.5.100 is not vulnerable. Summary: The target repository (Tomcat 8.5.100-tuxcare.10) contains the HTTP request line parsing feature described in CVE-2016-6816, but the vendor's fix has been applied. The fix was released in Tomcat 8.5.7, and the target version is much newer."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f7fc2f5-581f-59ec-9183-1218550935a0",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6817 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2016-6817 affects Apache Tomcat 8.5.0 to 8.5.6 and 9.0.0.M1 to 9.0.0.M11. The target repository is version 8.5.100-tuxcare.10, which already contains the fix that was applied in commit ee091b16f4 on October 20, 2016. The fix implements header size and count limits with exception throwing to prevent the infinite loop vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:391a6822-6eda-5b0b-9967-2655009d7e92",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e369fa94-e5b6-5ec2-a811-f9bb582e8ae9",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-8747 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2016-8747 is NOT present in the target repository. The target is Apache Tomcat 8.5.100-tuxcare.10, which already contains the fix introduced in version 8.5.10 (December 2016). The vulnerable buffer management code in the nextRequest() method has been replaced with proper buffer state handling that prevents cross-request data leakage."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a7a8c2c-6f27-5823-8b82-e98b9ada5c1a",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-12617 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2017-12617 has been fixed in the target repository. Both required patches preventing JSP upload via crafted HTTP PUT requests with trailing slashes are present in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37f19466-35a2-51c3-9408-15d537dbfd38",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:78938143-bd0b-51b4-bceb-27eec6356092",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5c90caab-1960-5cc5-a492-b95ccb34c365",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-5650 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2017-5650 affects Apache Tomcat 8.5.0 to 8.5.12. The target repository is running Tomcat 8.5.100-tuxcare.10, which is 88 minor versions beyond the affected range. Code analysis confirms the fix is present: when a GOAWAY frame is received, all streams including those waiting for WINDOW_UPDATE are properly closed and their threads are released, preventing thread exhaustion."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8e47725c-05f5-5e93-a23d-7c3637886e6e",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:978e9945-7a3a-58f2-aaa0-1e62f631e340",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-5664 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 The target repository (Apache Tomcat 8.5.100-tuxcare.10) already contains the fix for CVE-2017-5664. The DefaultServlet.service() method forces all error-dispatched requests to be processed as GET requests, preventing PUT/DELETE operations on static error pages."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3771da33-c45a-5048-bfef-3d11ee02750e",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-7674 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2017-7674 has already been fixed in this Tomcat version. The CORS Filter now correctly adds the HTTP Vary header when specific origins are configured, preventing cache poisoning attacks."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f8a91a9-b1fb-507d-8061-6caeefced229",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-7675 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2017-7675 affects Apache Tomcat's HTTP/2 implementation (versions 8.5.0 to 8.5.15 and 9.0.0.M1 to 9.0.0.M21), allowing directory traversal attacks via specially crafted URLs. The target repository (Tomcat 8.5.100-tuxcare.10) already contains the fix for this vulnerability, applied via Bug 61120 in May 2017."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:54425935-cdf3-5635-b69f-40834e3a0c01",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1304 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2018-1304 affects Apache Tomcat 8.5.0 to 8.5.27 where security constraints with URL pattern \"\" (empty string) were not correctly handled, causing them to be ignored. The target repository is version 8.5.100-tuxcare.10, which is much newer than the affected range. The fix was incorporated into upstream Tomcat 8.5.28 on February 6, 2018 via commit 5af7c13cff. The fix is present in the current codebase at RealmBase.java line 577, which explicitly handles empty string patterns by treating them as matching the context root ('/')."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f7123c39-6144-5987-a9ce-f73a2c8be469",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1305 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Version 8.5.100 is not vulnerable. Summary: CVE-2018-1305 is NOT present in the target repository. The vulnerable code pattern (lazy ServletSecurity annotation scanning) has been replaced with the fix (ServletSecurity annotations processed at web application startup). Target version 8.5.100 is newer than the affected range (8.5.0 to 8.5.27) and contains the fix applied in version 8.5.28."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6c41292-17ea-5d7b-bce8-26b484b6c3da",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1336 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 CVE-2018-1336 has been fixed in Tomcat 8.5.100. The vulnerability involving improper overflow handling in the UTF-8 decoder with supplementary characters was addressed in version 8.5.31 (commit e00812b94e, April 27, 2018). The fix is present in the primary decoding path (decodeHasArray method, lines 270-275), which handles array-backed buffers - the common case in Tomcat's usage."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f3b0a407-7845-5b1e-8866-ab17f7aab8c6",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-8014 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Tomcat Version 8.5.100 is not vulnerable to CVE-2018-8014. Confirmed by manual code inspection and security advisories."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d7d3d38-6836-569a-bfa5-82cf74163df0",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-8034 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Tomcat Version 8.5.100 is not vulnerable to CVE-2018-8034. Confirmed by manual code inspection and security advisories."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7e5b1ea6-0721-5824-87f4-0a99cb5c8344",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Version 8.5.100 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2020-11996. The vulnerability has been fixed with an optimized implementation that uses ConcurrentNavigableMap.subMap() instead of the vulnerable loop pattern. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4d70ac-0f1c-52ab-b825-a37ec6b953c9",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0f2cc6ad-0145-525f-bfb4-bae6b12993bf",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Version 8.5.100 is not vulnerable. Summary: The target repository is NOT vulnerable to CVE-2020-13943. The security fix has been applied: the concurrent stream limit check has been correctly moved from headersStart() to headersEnd(), preventing HTTP header leakage between requests. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1a50178f-d6ff-503d-9cc9-4b13685256f8",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.tomcat.embed:tomcat-embed-core 8.5.100.tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5dea036e-7ba2-5b8a-97f4-fd2138a6794e",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. already_fixed \u2014 The target Tomcat 8.5.100 repository already contains the fix for CVE-2020-9484. Path traversal validation was added to FileStore.java to prevent deserialization of attacker-controlled files outside the session storage directory. The fix is present at lines 347-350 using the improved Path API approach from the vendor's later commits."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31746747-34f6-59b6-88d3-1f08ce1d3029",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e044b703-64b7-5a3c-8c52-584eac0b43d0",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-42340 does not affect version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core. Version 8.5.100 is not vulnerable. Summary: Apache Tomcat 8.5.100-tuxcare.6 is NOT vulnerable to CVE-2021-42340. The target version is beyond the vulnerable range (8.5.60 to 8.5.71) and contains the necessary fix. [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:950a5ddc-2b89-5b4c-bbb6-43127624d39d",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:259797cf-6bda-5e6b-ab2a-c5b6edb35a7f",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b037e0dc-3112-50da-a4d1-1cce74359608",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a4b405e-a926-5952-b271-adbf5a124cf8",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f5484f0-14db-5931-96fe-c51c234177bb",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd209ff1-e146-50f3-a08d-0e68255c413a",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a04ffe0-87e2-5f02-bec5-c3cc3341e442",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b15908-d4ee-52ef-84ff-e7575d4204ad",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d5f8d16-e9c6-509e-a3f9-b19560408577",
      "id": "CVE-2024-52317",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52317 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:910db21d-2070-5111-8a2c-d214df4e6ba2",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b49df90-0a0e-5e7b-b896-fdf2036bc6a8",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9df77fa2-7916-5cd4-9b7e-a78173b7ecc8",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31650 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:715bb5fe-2b44-536a-a496-fabe1bce808c",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd07fc4b-144f-5079-9d66-4bab142ea18f",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d894a98e-7f41-54e8-baab-2614f0bdc022",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dddd68b4-bc10-5b5f-adce-712d39e17b2a",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9975ab3-59b8-5aa8-a702-349cdd7a08d3",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-49125 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:612a4be0-c887-5829-9840-3888ee9cf335",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c56afc2-8030-555b-b4ae-dd521dde7649",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52520 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7fd93151-630e-5c4f-8884-ecdcf77904d7",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-53506 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d2ba6b4-1616-5fd7-888d-5a3d2f2f89de",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55668 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5ef82fb9-8013-55d4-990d-314ed3f103a5",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5a6ce837-7b82-5cdb-bb7f-312662e59682",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55754 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06cfa46d-b9b5-58d3-93b1-d216492c8a74",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-61795 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c905652b-c8c7-57f6-ab4f-16a2f3ba813a",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2012a31-464e-5a0d-9f93-6b541585588c",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:86dc9ebb-9ed8-5124-9d52-811e6db7e061",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5bb26321-e292-552d-8cb1-cd8be009c9ec",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25854 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97be1f49-2e1f-58e9-828e-5b52f91d7b92",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8ef80d5d-2ff2-5e35-aa16-b42888b9a6ca",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5db9ab53-1094-5a78-9e6e-784af71df567",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:75cfa66a-3f4b-5c51-aa63-d48dfb4510de",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ec0454c8-ce3e-5bb0-8aed-aa26bd58ea50",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bbfe95c2-b799-5854-9900-9989a4d71f3b",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:329ab59e-8d8d-5ae9-a75c-12551682f679",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a903b0e2-c5c3-510b-90ab-eae4c5d50261",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e4867d8-9e9e-503a-8dc5-4b511538d92b",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f59c344-a602-59e1-b13f-8cd996ee1cab",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 8.5.100.tuxcare.1 of org.apache.tomcat.embed:tomcat-embed-core."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@8.5.100.tuxcare.1"
    }
  ]
}