{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:418541e4-768f-5861-a275-6d0856b9a86b",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1",
      "type": "library",
      "group": "org.apache.logging.log4j",
      "name": "log4j-appserver",
      "version": "2.11.0-tuxcare.1",
      "purl": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:27c21fb0-ff43-5e01-a315-12c01ecfebb1",
      "id": "CVE-2012-0881",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2012-0881 is fixed in version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:87ff3000-c7d0-5960-89cb-2b54bb535d22",
      "id": "CVE-2013-4002",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2013-4002 is fixed in version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d6c2227-1426-58a7-a5e1-394c07092c99",
      "id": "CVE-2018-2799",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2018-2799 is fixed in version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0c4575c2-d2a3-514e-8570-d51495cf09e8",
      "id": "CVE-2020-14338",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2020-14338 is fixed in version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0b555800-8d2e-5f19-826b-95bd730ed75c",
      "id": "CVE-2020-9488",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9488 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60779ec9-b9e0-526b-9a08-40752398e18d",
      "id": "CVE-2021-44228",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-44228 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd584da5-6769-5989-9247-19df6438dc5a",
      "id": "CVE-2021-44832",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-44832 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dd90032d-5bd7-5cbc-bc37-81490421c37f",
      "id": "CVE-2021-45046",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45046 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2dd3b2d8-a2ab-5829-a9b0-546c6ddbbeea",
      "id": "CVE-2021-45105",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-45105 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b097b9da-2d9c-53c3-bcfc-5243d19f8804",
      "id": "CVE-2022-23437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-23437 is fixed in version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e278e1d-9e64-5901-8001-db69d35423b7",
      "id": "CVE-2024-47554",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-47554 is fixed in version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a6f9da2-ba16-5208-adc3-13996de5fb8f",
      "id": "CVE-2025-68161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68161 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7ed2bddd-1cb0-55b6-a934-d11199f667a5",
      "id": "CVE-2026-34479",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34479 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e2cac9a0-070c-550b-a476-fe38ca002e82",
      "id": "CVE-2026-34480",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34480 affects version 2.11.0-tuxcare.1 of org.apache.logging.log4j:log4j-appserver."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.logging.log4j/log4j-appserver@2.11.0-tuxcare.1"
    }
  ]
}