{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3994e79b-6163-5331-b700-458668859e50",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-data-neo4j",
      "version": "2.4.6-tuxcare.6",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:4f489fd6-0f52-5f50-88b3-18d9008e61e6",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db9c6d73-4f88-52c5-afc7-6e684389f1ab",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fe84812-0cc7-5218-ae3d-6c3679c3be9e",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f248c4a-77bc-5e39-b1a9-1e478929ecde",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63e54ea1-7df3-5f10-8209-5cbb32428c4f",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c48a30e-b1c6-5fc5-bc24-8057dc15534b",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38807 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:06773202-a494-5cd5-ac60-6577fdec6139",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76bc0c23-109f-569f-bbaf-46e2f9338f1c",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd94321a-6cd8-53d3-bd08-d6dc7f74f323",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a969f09a-210a-5844-923a-af7beb7e6e5d",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:321f4626-bc04-58ef-a421-930368db225d",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3df163c9-5e3b-53f6-b2e5-ba46d9e144b5",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:576760d4-7b61-5f8c-aa7c-3e352238feb5",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de6d90eb-55f6-5a01-a8aa-120a6bad3ac7",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-40992 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6431986-1990-5aeb-8ea8-a6e010a91e86",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41001 affects version 2.4.6-tuxcare.6 of org.springframework.boot:spring-boot-starter-data-neo4j."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-data-neo4j@2.4.6-tuxcare.6"
    }
  ]
}