{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:1e8cc5ff-2999-5cda-a979-814fa166c969",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-orm",
      "version": "5.3.24-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:17c47b98-7882-580f-b78e-105bc343a382",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a062268-bcc6-5284-a0df-ce2c809e4cf1",
      "id": "CVE-2023-20860",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20860 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:20a9ab1b-7cbc-5865-af5b-b3b09abf1946",
      "id": "CVE-2023-20861",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20861 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cbe6e03e-ea8e-528d-85d1-8e68af183d45",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3c0c3406-5a2b-5123-9a56-5f098686b1b7",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:221be464-f0bd-532f-aad0-6d0df3d81a2f",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2eed814-6245-5436-bf12-8654e32b576b",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e62f181a-ca1d-5d87-a8c1-1d175c73cfee",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff4f7da6-f287-5801-8d3d-8c26c7e7c774",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f8e86664-25ad-5e9c-b845-203cad51cc7c",
      "id": "CVE-2024-38816",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:db7ff557-7619-583d-86cb-445e8a8e3c8c",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:01b645ae-5436-5ee0-8356-3730749ef89f",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73627193-9493-5eee-84a7-8cf1088ed23a",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d9eeae4-a36b-51f3-9d95-b4f2173e3ac8",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17e1aedc-98f9-5738-b80e-45bd4af35246",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4167eb3b-14e5-51df-bd0a-1f577eab980b",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41249 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd6fa1c8-a10e-5f3a-ad6c-172fa7c47f87",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:35dba524-d5e6-5638-9040-4b11c28db466",
      "id": "CVE-2026-22735",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c18623c3-937a-5efe-8f36-0b944f94cdd4",
      "id": "CVE-2026-22737",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22737 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a58e9d1a-f306-5800-a88d-08d14f8f17a4",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22740 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c847562f-aace-524d-a9f5-96d7a3a6cbca",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe106117-9eeb-5fa4-9acf-d8cff5b97d72",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:de719f94-5b9f-56fe-a30b-566a90d86189",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c9918d06-f6c2-52dd-b932-3d6aef4e1008",
      "id": "CVE-2026-41839",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41839 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b6e80342-e3fe-5dd8-84f2-b8c521b3b4c8",
      "id": "CVE-2026-41840",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.3.24-tuxcare.4 of org.springframework:spring-orm. Patches already applied: 7052da453285658215efc1dd5ecb0d472fde2de1 (already in target via 2c11852775 'Backport CVE-2026-22740 to 5.3.24')"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f12ed2c-1039-51c1-818a-39cfc9e25dcd",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ce6cef92-124a-5b0f-ad97-5494524c5ea1",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:534c8ff8-4b0d-593e-965a-d24af83e0883",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ad59a5c-38c1-5a8d-a6d4-eddf30b2434f",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41844 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:932ff5c8-e73e-5a1a-ba7d-1dff369b5ab7",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d378b63c-ba58-5754-b647-417d263f05bf",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c3e8e844-962f-5983-afb6-027561b6f13f",
      "id": "CVE-2026-41847",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:84be6001-bfbc-5279-9f39-b0ed32bafc3f",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:31001227-2881-5fbb-a01a-1e62df2841c0",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3190b24d-d361-5ec0-82dd-52a4ad375250",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1db11342-45d5-5f28-9c7f-7eaef636d1c5",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddcc298-f0d4-55c6-aba6-850124923591",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9c59bb45-1319-5fa8-9a20-eefdc3f6f31a",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c909e18b-985e-58a4-aee1-855558088e3a",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 5.3.24-tuxcare.4 of org.springframework:spring-orm."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-orm@5.3.24-tuxcare.4"
    }
  ]
}