{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:c2bde430-582b-533c-9edd-eff9b9e4c72b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-dbcp",
      "version": "9.0.50-tuxcare.12",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:ffae228c-43c3-50ce-9fad-90cb45238cee",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp. Version 9.0.50 is not vulnerable. Summary: The target repository contains a functionally equivalent fix for CVE-2020-11996. While the implementation differs from the provided patch, it addresses the same performance issue using a more efficient approach with ConcurrentNavigableMap.subMap(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1706894e-8c80-5a57-8672-4d4c4003569a",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61372637-234e-5078-8011-327272e2b58a",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp. Version 9.0.50 is not vulnerable. Summary: Target repository already has the fix for CVE-2020-13943 applied. The maxConcurrentStreams check is correctly located in headersEnd() method, not in headersStart(). [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:451574d2-1107-5772-b7db-9251531814d6",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-9484 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp. Fix already present in baseline since 9.0.35. Verified in java/org/apache/catalina/session/FileStore.java:303 \u2014 canonicalFile.toPath().startsWith(storageDir.getCanonicalFile().toPath()) containment check is in place. Advisory range 9.0.0.M1-9.0.34; 9.0.90 is well past the fix."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2371c67a-16f2-5495-9618-0082ffca77f9",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:611229c7-f50f-507c-a3c5-7b237ce584a8",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a44c9959-6343-543d-9444-12dec809e81e",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fdf51fc-5043-5c8a-94f5-b7f814c3607d",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0a4292f-b954-5387-8b0b-999379cdc025",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8687c655-eaa7-5a4e-a2e1-cf9ef05fc1ff",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd3f5f98-4103-57f8-b478-90889ca2bf99",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00db9c79-cb99-5af5-9c7b-6113cc94a1b0",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff9ef8c8-1e3a-5e98-9323-45728f79253b",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-24998 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2f4a7c3-4109-54a0-b242-2e4a5a0167cf",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:97005c3a-8225-5faf-96cb-94aa226322f6",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d93dd0c-3a8b-5dfb-9532-70b938019546",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61a806b2-4849-55ab-8656-e174ac0d0abf",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-42795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9f1c441d-b569-55f6-898c-a3c019213eb3",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-44487 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dfb11848-cae2-51de-8257-1d225fac5015",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8bd2b50a-6e71-5a5c-8955-2e09996e9020",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-46589 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d29147a8-7ee5-5710-a6ac-9bb0ab9e9aff",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:576debf9-cf41-585d-9fe6-b46c700b292c",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d4de17d-eaba-5a25-84f4-23b12a397fbd",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-34750 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00b76f44-a0bd-5ef3-a927-82cedcbd4109",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60e3a2a2-f634-52c9-bed0-745dc0230624",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a2a2e07e-7799-5d54-9b75-aaeb219d8d1d",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdaa1dcc-0f7e-5967-9fbf-5ad149315d1d",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8210ea3e-6f94-560d-aac7-1e9ddc27514f",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-56337 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f754190f-1fd2-5eae-91f8-8dbd80897ce4",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:131777ff-58fb-59b7-bef7-de65c53126c8",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp. 9.0.50 predates HTTP/2 RFC 9218 PRIORITY_UPDATE frame support (added in 9.0.76). Advisory range per NVD/Snyk/GHSA is 9.0.76-9.0.102. Code inspection confirms: Http2Parser.processFramePriorityUpdate method and priority parsing in Stream.emitHeader do not exist in this baseline. Vulnerable code path is absent."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b757cd-4902-5bde-a401-df5fbd86779a",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0dc417b-56f1-5954-8ee2-a3020e99a3d1",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eae9505a-734c-59c1-8960-ab001ca23de3",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da4b7b0f-5e05-5731-aaee-613077befddc",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48989 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a283d0f7-08c4-5c04-9016-821fd6114348",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4324899-98b5-5040-bef6-c108c028226c",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d2165869-696a-52f4-b807-970595a7ceb2",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52434 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5eb77fe-7d63-545f-8d0c-e115f6505e90",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2527f012-2765-5ef1-9f98-c75f48b9cfd3",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df8944b1-430c-5c07-8ae1-9c520112e0d1",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2926052-b8f2-50aa-a888-148e34d45113",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-55752 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4686b0f-b0cb-50c0-9e81-0418c76768af",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2cfe3435-15fe-5bdd-aa06-4a896a24cebe",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:907be8da-9f83-52b4-8b22-db4acf746530",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-66614 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:15b7f993-1f51-5406-9ea5-c0d6913c0442",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ef313f2-7c38-5f65-ace1-eccd892eb766",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65b2a9a1-7744-5f43-bb82-b92396aa55e7",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5794ffa-132f-5c20-bcf3-67f533f97636",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0761a3cd-0e35-5b8a-ad01-25dcd5995a87",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a896e94d-8de6-530c-95a5-817d822055e1",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fa4bd22-e05c-5080-9add-eeb7b07d403c",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a459f430-9feb-5384-9dd2-45fabff000a5",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:04b29d56-82cb-5247-b742-f4decfaa8ab4",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d22136c4-8a89-5bff-80b0-87aed9c8acaf",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:89f9b1c0-bc03-52e9-ae55-bb957c68be7e",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf03df48-9d49-539c-91cd-180329e21f3b",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bacc3725-472e-5256-bfd6-6e30056d5ff3",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24783906-34f3-5420-b20d-802500fc13e1",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:edbabe22-39f0-5782-9b38-338473e88283",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 9.0.50-tuxcare.12 of org.apache.tomcat:tomcat-dbcp."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-dbcp@9.0.50-tuxcare.12"
    }
  ]
}