{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:e3cd584f-1f9b-51d9-b2cf-e1494e0990a5",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-el-api",
      "version": "7.0.109-tuxcare.3",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:51950c80-e64c-5067-9d38-bd9edc4c184c",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-4590 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7696bac7-215f-5436-81f4-6eec57868dd1",
      "id": "CVE-2015-5174",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5174 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7ef215b-2d8a-59ff-b100-9a4ca48c01be",
      "id": "CVE-2015-5346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5346 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca9e31b5-776e-5b53-a00c-33d68c96291b",
      "id": "CVE-2016-0706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0706 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0eed43ed-8582-5f7a-8237-df182907fbc5",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81b30156-622b-58ed-a116-3effbcd5a41c",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:648d1cdd-a298-59f1-b3fa-00937b71cff1",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a301c89-40f4-5de4-9ac1-db0f18d9963f",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db1d50c4-afa1-531b-8937-769f874b6acb",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9f6c828-933d-50e3-9ccc-a6a9287f5ce1",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e4c71cda-bc74-5cb3-be1c-9066df4239ac",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6816 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: CVE-2016-6816 is NOT present in this target repository. The target is running Apache Tomcat 7.0.109, which includes the fix introduced in version 7.0.73. The fix adds stricter character validation for HTTP request line parsing using HttpParser.isToken(), HttpParser.isNotRequestTarget(), and HttpParser.isHttpProtocol() methods."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f58b4654-d509-568e-ad23-714c9eb9eb4b",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6817 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: Target repository is Tomcat 7.0.109-tuxcare.1, which does not have HTTP/2 support. CVE-2016-6817 affects the HTTP/2 header parser in Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6. Since HTTP/2 support was first introduced in Tomcat 8.5 and 9.0, and the target is running Tomcat 7.0.x, the vulnerable component (java/org/apache/coyote/http2/Http2Parser.java) does not exist in this codebase. Therefore, the vulnerability cannot exist."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bb46066a-8338-51e6-85d8-cd6d84c5b928",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:549c126d-1a34-5ecf-9ee0-ed21afde4cfa",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-8747 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: CVE-2016-8747 does not affect the target repository. The target is Tomcat 7.0.109, which uses a fundamentally different architecture (byte arrays with System.arraycopy) that predates the vulnerable ByteBuffer refactoring introduced in Tomcat 8.5.7. The vulnerable class Http11InputBuffer.java does not exist in Tomcat 7.x."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b8534279-11ba-5efd-9e06-d40777118a67",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c8dd6e6f-018d-5f18-ac5b-817a6860a56d",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:62e1436b-ea9c-5696-8c24-62bce17587be",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc900f3f-01d7-5a1d-91b2-e963e4608334",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-5650 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: Target repository (Apache Tomcat 7.0.109) does not contain HTTP/2 implementation. CVE-2017-5650 affects HTTP/2 GOAWAY frame handling in Tomcat 8.5.0-8.5.12 and 9.0.0.M1-9.0.0.M18. HTTP/2 support was first introduced in Tomcat 8.5.0, so Tomcat 7.x completely predates the vulnerable feature."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4d179595-3ec7-5573-8ccc-c6e13886f404",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5651 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0dacb4a8-9dfc-599b-95ce-55a3c0aebef3",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:94eb490e-5320-5a6d-aca7-8666e824a3c5",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82362374-9a74-582b-ae80-85fdd2953c81",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-7675 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: Target repository is Tomcat 7.0.109, which does not contain HTTP/2 support. The vulnerability CVE-2017-7675 is specific to the HTTP/2 implementation that was introduced in Tomcat 8.5.0 and 9.0.0.M1. Since the vulnerable feature (HTTP/2) was never introduced in Tomcat 7.x, the target is not vulnerable."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bf6d3b98-893a-5577-8d5f-4fd471dc3f32",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b702edb-5954-53a6-a58d-936cd5f50a90",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1305 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: Target repository (Apache Tomcat 7.0.109) is NOT vulnerable to CVE-2018-1305. The vulnerability affected versions 7.0.0 to 7.0.84, and was fixed in 7.0.85. The target version includes the complete fix: ServletSecurity annotations are processed at application startup rather than lazily at servlet load time, eliminating the timing-dependent security constraint application issue."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2ef2488-5d6f-56a1-a1c5-9628bdea2e3e",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-1336 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Patches already applied: e00812b94e5830b2be3de04f4ae4ade38a700074 (already in target via 156d76a6af 'Improve handing of overflow in the UTF-8 decoder with supplementary characters.')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:665fa7dc-d7df-5f81-a965-f86f54cb8951",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-8014 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. already_fixed \u2014 CVE-2018-8014 fix is already present in the target repository. The target (Tomcat 7.0.109-tuxcare.1) contains commit 5877390a96 which addresses the insecure CORS filter defaults. All three critical security changes from the vendor patch are present: (1) DEFAULT_ALLOWED_ORIGINS changed to empty string, (2) DEFAULT_SUPPORTS_CREDENTIALS changed to false, and (3) validation logic added to prevent t..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ab718aa-2a3b-5828-9dd3-8667a9884b61",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7b5d95e7-575b-564f-b14b-d60b81958d8c",
      "id": "CVE-2019-12418",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2019-12418 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. already_fixed \u2014 CVE-2019-12418 has been fixed in this Tomcat 7.0.109-tuxcare.1 repository. The security fix from commit bef3f40400 (November 14, 2019) is present. The vulnerable standard RMI registry that allowed bind/unbind/rebind operations has been replaced with a custom immutable JmxRegistry class that prevents registry manipulation attacks."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:165c206a-68f6-55fe-9be8-27e77a23640c",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bab0d237-d07f-5c7a-a53a-5c7275f69146",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ba63be0-4b57-51d4-b94e-0b5a3c184d36",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31d7a7cf-1727-59dc-abc5-698e20cced53",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.tomcat:tomcat-el-api 7.0.109-tuxcare.3."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e6da6fb8-dd84-5e4b-b560-c1b4c3cdd56a",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0202acb4-58db-54bb-8732-abf795bef45b",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df9e74c4-1764-5c37-85ed-4cedddcc25fe",
      "id": "CVE-2021-30639",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-30639 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1dc4f8b2-4187-5ffe-a8fb-0523e8bd9d01",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-42340 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f60b0584-a6d2-5f74-afe9-def6f918d02a",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23181 is fixed in version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f9b8321d-0dde-567b-8d88-b241e6157924",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-34305 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7d8c8c8-775c-59f2-b150-c13f1dc66488",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-45143 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:52f5a4ea-5bfd-5493-9903-ea6e2dff08a1",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93cc0d10-f90a-5410-8db8-a614758582c2",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38286 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5433062b-1b2b-515f-992c-f44af19c90db",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52316 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce9f0008-d8ca-5838-ac34-b824bf3aa84a",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6516c2c0-71ca-54a6-809a-6e1ea2d05c7b",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31651 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e2709d5-5be3-5666-bf31-daf491e9326b",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3d40e88b-4e6c-513c-8181-c2548589f220",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-49125 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. Version 7.0.109 is not vulnerable. Summary: CVE-2025-49125 does not affect this Tomcat instance. The target is running Tomcat 7.0.109, which predates the introduction of the vulnerable PreResources/PostResources features. These features were introduced in Tomcat 8.0 as part of the WebResourceRoot API. The CVE explicitly lists only Tomcat 9.x, 10.x, and 11.x as affected versions."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:74cc1d6d-bfe4-5258-a9e0-2b5ee1a4d3d4",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:581c107d-8bc6-5df7-a239-16c0ab2fb00f",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:70019d1e-9f5c-5e4f-988b-f46af292fa6e",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24880 is fixed in version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d205651b-64fc-55d9-9d46-5ac470f11252",
      "id": "CVE-2026-29145",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29145 does not affect version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api. The official CVE record (https://www.cve.org/CVERecord?id=CVE-2026-29145) limits the affected versions to Apache Tomcat 9.0.13\u20139.0.115, 10.1.0-M7\u201310.1.52, and 11.0.0-M1\u201311.0.18. Version 7.0.109 is not within any of these ranges"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1991e1e-92ee-5fc4-ad2e-173127b04a71",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29146 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:69c659e1-db6c-5335-b849-66f3043725de",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6a3b2327-968b-5ffd-ac97-976e0c340a9b",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf91e547-3048-5b63-8b35-aad0d72fc05c",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41293 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dc948fd-69c0-571b-a09a-95807afdb3a6",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-42498 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dca43cca-8ad2-559c-94b1-abbdb8a2a771",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7bc3c97-30d1-5dfe-acb4-559f9b92f174",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5774d2d7-b56e-5041-bb88-458643de8518",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a081ec42-36dc-5300-a357-8031160f6a28",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 7.0.109-tuxcare.3 of org.apache.tomcat:tomcat-el-api."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-el-api@7.0.109-tuxcare.3"
    }
  ]
}