{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:b7cdea02-ae48-57ee-b56e-1d7eaea0c92b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2",
      "type": "library",
      "group": "org.apache.activemq",
      "name": "artemis-jakarta-ra",
      "version": "2.33.0-tuxcare.2",
      "purl": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:8a59932c-4f6f-5548-b6e0-a8ee0bbf42b1",
      "id": "CVE-2010-0684",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2010-0684 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9fe07596-2967-5ae1-94d4-bdd50fa3d64a",
      "id": "CVE-2010-1244",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2010-1244 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09f687cc-1269-5764-a66b-7635e8d90e31",
      "id": "CVE-2011-4905",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2011-4905 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2011-4905: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc5549fa-20cd-5615-83dc-1c3d1cb9a9b9",
      "id": "CVE-2012-5784",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2012-5784 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2012-5784: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c456c016-bbcb-5647-846b-d838aed770d9",
      "id": "CVE-2012-6092",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2012-6092 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:478d4377-399a-508f-9e94-944cec71681d",
      "id": "CVE-2012-6551",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2012-6551 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:00c71529-9252-50df-9833-fc4615807f78",
      "id": "CVE-2013-1879",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-1879 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:738582a4-c5e2-507e-86f9-e06c54c4f41d",
      "id": "CVE-2013-1880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-1880 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6212e20-1eee-57fd-a042-bfac34186354",
      "id": "CVE-2013-3060",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2013-3060 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:23a5ada0-5df1-589e-99ce-e6981a8ce434",
      "id": "CVE-2014-3576",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2014-3576 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9239e8c2-3744-52d1-a5bb-e3d0df857a4f",
      "id": "CVE-2015-7559",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2015-7559 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2015-7559: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:22dc7e1d-1a23-57a4-b080-2f39d392330f",
      "id": "CVE-2018-11775",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2018-11775 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2018-11775: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a5c00e9-9339-59e4-b821-077e8468e9a5",
      "id": "CVE-2018-8909",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2018-8909 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2018-8909 concerns the Wire application for Android, which is a completely different product from the target repository (Apache ActiveMQ Artemis). The affected component AssetService.scala and all Wire application code are absent from this repository. This is a wrong-project match."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:520d7b66-c02a-50db-94ec-726bdc8e944c",
      "id": "CVE-2020-13920",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13920 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90e7c2d4-d88d-5b4b-b786-9fa97c9d769c",
      "id": "CVE-2020-13947",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13947 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b78d0443-a134-5da8-b912-33a212f77dea",
      "id": "CVE-2020-15258",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-15258 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2020-15258 is a wrong-project match. The advisory concerns Wire (an Electron-based secure communication application), but the target repository is Apache ActiveMQ Artemis (a Java-based message broker). The vulnerable component (shell.openExternal Electron API) and affected product code are entirely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a58acae-66da-5463-95c7-a85a3959eb31",
      "id": "CVE-2020-26217",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-26217 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2020-26217: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dd26693-99dc-51b0-9ff8-a72023b16459",
      "id": "CVE-2020-27853",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-27853 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2020-27853 is a wrong-project match. The CVE concerns Wire AVS (Audio, Video, and Signaling), a C-based WebRTC library used in Wire Secure Messenger applications. The target repository is Apache ActiveMQ Artemis, a Java-based enterprise message broker. No Wire AVS code, dependencies, or related components exist in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:93c1c0bc-a7e5-56ea-a042-86ef97265cf4",
      "id": "CVE-2021-21301",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-21301 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2021-21301 concerns Wire for iOS, a mobile video calling application. The target repository is Apache ActiveMQ Artemis, a Java-based message broker with no video/camera functionality. This is a wrong-project match with no containment relationship."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f357e06-61de-5a03-99d4-6023f5e25d9e",
      "id": "CVE-2021-21341",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-21341 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38307ef6-1fb6-58c9-afbd-bfc08ed3a2c3",
      "id": "CVE-2021-21342",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-21342 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2021-21342: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:804ca851-57f2-5c01-82c2-346dd001603b",
      "id": "CVE-2021-21343",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-21343 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. All 1 patch commits already exist in target branch"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dba31a9d-0111-5be1-b284-efeefd4cb795",
      "id": "CVE-2021-21345",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-21345 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef43bd62-5b92-5eee-b284-5720e1e9233c",
      "id": "CVE-2021-21346",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-21346 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a0a13f69-e3ee-5545-b8df-d1c5597f32dd",
      "id": "CVE-2021-21347",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-21347 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2021-21347: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1bc1bd98-da38-5f1e-a36d-d9527d00a38f",
      "id": "CVE-2021-21349",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-21349 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2021-21349: the security fix is already present in the target branch. Momus prerequisite check: \"All 1 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3f63640f-75a0-5fd8-ac74-ed123211bee5",
      "id": "CVE-2021-21350",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-21350 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8a8dd363-0672-563c-80b6-70de526aa0d9",
      "id": "CVE-2021-21351",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-21351 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2b1fd081-3110-517e-a588-41dbeda7b232",
      "id": "CVE-2021-32665",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-32665 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2021-32665 concerns wire-ios (an iOS messaging app), but the target repository is Apache ActiveMQ Artemis (a Java message broker). This is a wrong-project match with no code relationship between the two products."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6029231c-a9ea-5c8b-b8af-30ff5a32e5eb",
      "id": "CVE-2021-32666",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-32666 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2021-32666 concerns wire-ios (an iOS secure messaging app), but the target repository is Apache ActiveMQ Artemis (a Java message broker). This is a wrong-project match with no code relationship."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:663a677f-a61b-59e3-b619-be374da673d9",
      "id": "CVE-2021-32755",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-32755 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2021-32755 concerns Wire iOS Transport (wire-ios-transport), an iOS framework for the Wire collaboration platform. The target repository is Apache ActiveMQ Artemis, a Java message broker. These are completely different products with no dependency or containment relationship. The affected component (iOS websocket implementation with missing certificate pinning) does not exist anywhere in thi..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a7e783ae-dda7-50a0-a4f5-7d47649849b9",
      "id": "CVE-2021-41093",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2021-41093 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2021-41093 concerns Wire (an iOS secure messenger application), but the target repository is Apache ActiveMQ Artemis (a Java message broker). These are completely different products with no relationship. The affected component (Wire iOS application code) is entirely absent from this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d4d62059-94f0-54b4-9706-c8ae4f836411",
      "id": "CVE-2022-23625",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-23625 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2022-23625 concerns Wire-ios (wireapp/wire-ios-transport), an iOS messaging application written in Swift/Objective-C. The target repository is Apache ActiveMQ Artemis, a Java-based message broker. These are completely different products with no code relationship."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8f28dc42-8412-5e62-bf11-c0cf23ae005d",
      "id": "CVE-2022-31009",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-31009 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2022-31009 concerns wire-ios (an iOS Wire client mobile application), not Apache ActiveMQ Artemis (a Java message broker). This is a wrong-project match with no relationship between the advisory's affected product and the target repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f796e46-603d-5c4b-acd4-3df62d0fe0f8",
      "id": "CVE-2022-41678",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-41678 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d703bac3-14cd-5f78-9b04-030c4b5b6ea1",
      "id": "CVE-2022-43673",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2022-43673 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2022-43673 concerns Wire (an Electron-based messaging client application) through version 3.22.3993 on Windows. The target repository is Apache ActiveMQ Artemis 2.33.0-tuxcare.1, a Java-based message broker. These are completely different products with no dependency relationship. The affected component (IndexedDB storage handling in Wire's Windows client) does not exist in this repository."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:677d5b8c-a307-5a53-a514-ab2a9f76b45d",
      "id": "CVE-2023-22737",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-22737 is a false positive for org.apache.activemq:artemis-jakarta-ra 2.33.0-tuxcare.2. false_positive \u2014 CVE-2023-22737 concerns wire-server (a team communication platform), but the target repository is Apache ActiveMQ Artemis (a message broker). This is a wrong-project match with no relationship between the two products."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7d9a5ddc-ff14-5fe5-9156-52be9d801a42",
      "id": "CVE-2023-46604",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-46604 does not affect version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra. Version 2.33.0 is not affected by CVE-2023-46604: the security fix is already present in the target branch. Momus prerequisite check: \"All 2 patch commits already exist in target branch\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:76ef5590-0f36-5bfd-8f42-19626599445a",
      "id": "CVE-2025-27391",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-27391 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2eaaed6f-5064-58bd-b226-e8cb45123b9b",
      "id": "CVE-2025-27427",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-27427 is fixed in version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dbc7ee5-c79b-5fd6-aa41-5875c00da6db",
      "id": "CVE-2025-66168",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66168 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5247420e-0768-52dc-b2c0-38e133f94b93",
      "id": "CVE-2026-27446",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27446 is fixed in version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8d97bfd4-ceff-537c-91a0-bad668d78166",
      "id": "CVE-2026-32642",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32642 affects version 2.33.0-tuxcare.2 of org.apache.activemq:artemis-jakarta-ra."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.activemq/artemis-jakarta-ra@2.33.0-tuxcare.2"
    }
  ]
}