{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:70d9f94a-9ada-5570-97e2-8da747c55bde",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-jdbc",
      "version": "4.3.9.RELEASE-tuxcare.1",
      "purl": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:f8eea61d-680d-51e4-9ba6-ac62916ef6ae",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84e32123-436b-55e0-910d-01d13de43898",
      "id": "CVE-2018-11039",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11039 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:39b940b5-f83b-5cbb-a737-3457d2a4d977",
      "id": "CVE-2018-11040",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-11040 is fixed in version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4b1db486-7c29-5f85-aacc-c86bdbee0b69",
      "id": "CVE-2018-1257",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1257 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dce27c7e-8233-59a4-81b0-3665d787aaea",
      "id": "CVE-2018-1270",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1270 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3b2cfb75-5dce-5ab1-aed3-04479439857e",
      "id": "CVE-2018-1271",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1271 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9da508c-b7d1-5fb4-bf8d-878f7400c215",
      "id": "CVE-2018-1272",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1272 is fixed in version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c7ffcd03-7f61-5d2d-8038-a95a1baf5ad6",
      "id": "CVE-2018-1275",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-1275 is fixed in version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe12bc8d-6337-586a-8d45-cda765d72f60",
      "id": "CVE-2018-15756",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-15756 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6c2e1a0-a07b-548d-8379-3e43a71387aa",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc. already_fixed \u2014 The target Spring Framework 4.3.9.RELEASE already contains the fix for CVE-2020-5421. The critical defense mechanism (removeJsessionid) that prevents jsessionid path parameters from bypassing RFD protections has been present since 2015 and was never removed from the 4.3.x branch."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af1ca58c-52ed-5501-8de6-2525a8e36e26",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f1cb3e0f-66e4-5ed5-8b58-798660eaa518",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc. not_affected \u2014 Spring Framework 4.3.9 is not affected by CVE-2021-22118. This vulnerability is specific to Spring WebFlux (introduced in version 5.0), which does not exist in Spring 4.3.x. The vulnerable classes SynchronossPartHttpMessageReader and DefaultPartHttpMessageReader are part of the reactive multipart handling in WebFlux and are not present in version 4.3.9. Spring 4.3.9 uses Apache Commons FileUplo..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:359c47c4-8665-556d-8de6-3bc7610792e7",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22950 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d1259e50-e7cf-5b8a-a576-2a610801c175",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22965 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2651864d-3ae6-5772-b613-673d9ae1eca7",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4dedf85e-6ff3-531d-a32f-fea7b0211ba3",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d93d0611-206f-5cc8-8686-92d0f49f59aa",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5fe8998c-bf9c-5b09-a293-d57e79a0c9af",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29574dbe-964b-556b-b177-69ca27df1952",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8ab50ed-8385-5ced-b303-be4ab8fa6034",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:891ece67-6463-5b10-829b-bbb924d6078d",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ab5d7ac2-5931-5d3b-8579-5737e6a7aff9",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24885c6c-f6ed-55c8-b3ee-23d04237b2e8",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:42c5635f-e455-5db3-9b8c-652b7fe746fc",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38809 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcd422a7-e59a-5918-98f3-5300cb8ce383",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc. not_affected \u2014 Spring Framework 4.3.9.RELEASE is not affected by CVE-2024-38820. This version does not contain the CVE-2022-22968 fix that introduced locale-dependent toLowerCase() calls in DataBinder's disallowedFields mechanism, so the specific locale-dependent case conversion vulnerability that CVE-2024-38820 addresses is not present. However, 4.3.9 is vulnerable to the predecessor vulnerability CVE-2022-2..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28930e81-0ce7-534f-9a3a-0880104975b9",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:67fda9ac-f27d-5769-9385-b2df7db30514",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f000c8d-98f2-5c87-baf2-2423f9413793",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41254 affects version 4.3.9.RELEASE-tuxcare.1 of org.springframework:spring-jdbc."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-jdbc@4.3.9.RELEASE-tuxcare.1"
    }
  ]
}