{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:3136bf3c-0cc1-51ff-a4e4-e8482016a958",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-i18n-ja",
      "version": "7.0.70-tuxcare.1",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:add6fae8-7964-541c-a485-86768cc57934",
      "id": "CVE-2012-5568",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2012-5568 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02f4b311-a637-5eda-892e-15e501853b6a",
      "id": "CVE-2013-4590",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2013-4590 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. not_affected \u2014 Apache Tomcat 7.0.70 is not affected by CVE-2013-4590 (XXE vulnerability). The vulnerability affected Tomcat versions before 7.0.50. The target version 7.0.70 contains upstream Apache fixes (commits 78dd7e6f3d and f074781590) that implement and enable XXE protection by default. The LocalResolver entity resolver blocks external entities not in well-known whitelists, with xmlBlockExternal default..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:945ef7a7-368e-55c0-ac0a-b89cc7f22d37",
      "id": "CVE-2015-5174",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5174 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38c40d60-47f8-53bf-91a4-aff88ace62c4",
      "id": "CVE-2015-5346",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2015-5346 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d203c889-7918-5b9b-9949-877d5b7f274f",
      "id": "CVE-2016-0706",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0706 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3467fa5-d185-57b2-90af-ab464fdbc2fe",
      "id": "CVE-2016-0762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0762 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:38d44e87-c27f-5008-a0c4-6e998741196a",
      "id": "CVE-2016-0763",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-0763 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dcec2974-be28-583f-a515-5c75cd94b837",
      "id": "CVE-2016-5018",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5018 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cd209908-c6ae-534e-8330-d5e1bfae7238",
      "id": "CVE-2016-5388",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-5388 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b558ed6-2914-5f31-a5ae-f8f0bba885d7",
      "id": "CVE-2016-6794",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6794 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e3822ef7-6b08-5084-9132-fda7fae5d831",
      "id": "CVE-2016-6796",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6796 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cf6fbaea-7707-575b-b02e-19f59baff290",
      "id": "CVE-2016-6797",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6797 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7326c4d9-5f0d-5d96-93d2-c89eef1f3d05",
      "id": "CVE-2016-6816",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-6816 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7428872b-c5dc-57a2-9ec7-01d8adaad4a0",
      "id": "CVE-2016-6817",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-6817 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Apache Tomcat 7.0.70 is not affected by CVE-2016-6817. This CVE concerns an infinite loop vulnerability in the HTTP/2 header parser (Http2Parser.java) when processing headers larger than the available buffer. The target version 7.0.70 predates HTTP/2 support in Tomcat, which was introduced in version 8.5.0. The entire org.apache.coyote.http2 package is absent from this version. Without HTTP/2 implementation code, the target cannot receive or process HTTP/2 header data, making the vulnerability pattern impossible to manifest."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4e8c98a8-4727-54b7-a397-7468cde2e265",
      "id": "CVE-2016-8735",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8735 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d0a0b04-c9ba-5df0-a6d2-1e015d733b49",
      "id": "CVE-2016-8745",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-8745 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:65c27896-caeb-5176-8221-a723ed5456ce",
      "id": "CVE-2016-8747",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2016-8747 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. CVE-2016-8747 affects Apache Tomcat 8.5.7-8.5.9 and 9.0.0.M11-9.0.0.M15 due to ByteBuffer state mismanagement introduced during refactoring. Tomcat 7.0.70 uses a fundamentally different architecture based on byte arrays with correct arithmetic in AbstractInputBuffer.nextRequest(), predating the vulnerable ByteBuffer refactoring. The specific vulnerable code pattern (incorrect limit calculation after ByteBuffer.compact()) does not exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8abf4797-2b07-5252-b71e-ed8f5dd8d08b",
      "id": "CVE-2017-12615",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12615 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ea7edc2-d3a4-5905-969e-73a9ef57fad3",
      "id": "CVE-2017-12616",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12616 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bc9c4f60-bb7b-5b17-b155-bbe29eadd0fc",
      "id": "CVE-2017-12617",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-12617 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b461c0a8-7969-5b80-bddc-5cdf5ad948aa",
      "id": "CVE-2017-5647",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5647 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da537ed9-8754-5036-95ce-df202d57d77b",
      "id": "CVE-2017-5648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5648 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:575d1ba3-b188-546c-a190-d79b62d32fd3",
      "id": "CVE-2017-5650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-5650 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Apache Tomcat 7.0.70 is NOT AFFECTED by CVE-2017-5650. This vulnerability concerns HTTP/2 GOAWAY frame handling that could lead to thread exhaustion. Tomcat 7.0.70 does not have HTTP/2 support - the entire org.apache.coyote.http2 package and Http2UpgradeHandler class do not exist in this version. HTTP/2 support was introduced in Tomcat 8.5.0; version 7.0.70 only supports HTTP/1.1 and AJP protocols. The vulnerability's attack vector (HTTP/2 streams waiting for WINDOW_UPDATE when GOAWAY is received) relies on HTTP/2-specific flow control mechanisms that are absent from this codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2d947a6c-9659-504c-ae6b-eaff8bd0fba8",
      "id": "CVE-2017-5651",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-5651 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2017-5651. This vulnerability was introduced during the HTTP connector refactoring for Tomcat 8.5.x onwards and does not exist in Tomcat 7.x. The target uses a pre-refactoring architecture with separate sendfile state tracking via the `sendfileInProgress` boolean flag, which inherently prevents the race condition that allows a Processor to be added to the cache twice. The vulnerable code pattern (relying solely on `sendfileData != null` for state determination) is not present in version 7.0.70."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3a84c922-c1ce-5a88-9619-eaff834866fd",
      "id": "CVE-2017-5664",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-5664 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:374ec5a4-687a-5a04-bce6-24df7e759115",
      "id": "CVE-2017-7674",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2017-7674 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c88bc419-7271-5769-86db-db2b503e67be",
      "id": "CVE-2017-7675",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2017-7675 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. CVE-2017-7675 is a security-constraint bypass in the HTTP/2 implementation of Apache Tomcat. The flaw is in org.apache.coyote.http2.Stream: while processing the ':path' pseudo-header of an incoming HTTP/2 request, the request URI was stored with MessageBytes.setString(), which keeps it as a String and so skips the byte-level URI parsing that extracts and removes path parameters. Path parameters - and the directory-traversal sequences they can carry - were therefore never processed, so the path used for security-constraint matching could diverge from the path actually served, and a specially crafted URL could evade those constraints. Apache addressed it in 8.5.16 by setting the URI as ISO-8859-1 bytes instead (svn r1796091, Bugzilla 61120), and records the issue as affecting 8.5.0 through 8.5.15 and 9.0.0.M1 through 9.0.0.M21. Apache Tomcat 7.0.x has no HTTP/2 support of any kind. The org.apache.coyote.http2 package first shipped in Tomcat 8.5.0 and was never added to the 7.0.x line. In 7.0.70, java/org/apache/coyote/ contains only the http11 and ajp protocol implementations, there is no Stream class, and no file in the source tree references HTTP/2 in any form. The only protocol handlers the release provides are Http11Protocol, Http11NioProtocol, Http11AprProtocol and AJP/1.3; Tomcat 7 has no UpgradeProtocol extension point through which an HTTP/2 implementation could be plugged in, and no bundled or declared dependency supplies one. The vulnerable code is therefore absent from this version, and the bypass it enables cannot occur."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:feba56e3-19af-5327-adfe-a649ebda69c1",
      "id": "CVE-2018-11784",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-11784 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c6c51bc5-cc46-561e-94b4-5487614b63b1",
      "id": "CVE-2018-1304",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1304 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1323714d-8a6c-5520-804d-c2445e8afa75",
      "id": "CVE-2018-1305",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1305 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0a557cdf-ac08-5806-99f8-a31d94ca01a2",
      "id": "CVE-2018-1336",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-1336 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:055f3bc2-8bfb-531a-b73a-6ea0dffb1252",
      "id": "CVE-2018-8014",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8014 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b7fd6e27-7ddf-5253-921b-f10d7ea9b2a4",
      "id": "CVE-2018-8034",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2018-8034 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef16cc5b-1685-580c-b138-e7cb45dccc25",
      "id": "CVE-2019-0221",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0221 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9a3e9eb9-dfca-5d05-86a7-64d862200937",
      "id": "CVE-2019-0232",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-0232 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b3891472-9a7f-566f-9ca7-a3469d0300f0",
      "id": "CVE-2019-12418",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-12418 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6b9c47f1-c3f8-548f-a34c-c534172005a2",
      "id": "CVE-2019-17563",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-17563 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fc94690-85e5-5590-b668-86bcdb84c5d5",
      "id": "CVE-2019-2684",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2019-2684 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2e3ef739-4e7c-5568-b841-1c9763d5150f",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-11996 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Apache Tomcat 7.0.70 is not affected by CVE-2020-11996. This vulnerability is specific to HTTP/2 stream handling in the Http2UpgradeHandler.closeIdleStreams() method, which exhibits O(n) time complexity where n is the stream ID value when processing large stream IDs (e.g., Integer.MAX_VALUE - 8). Tomcat 7.x versions do not have HTTP/2 support - the entire http2 package is absent. HTTP/2 was introduced starting with Tomcat 8.5.0. The target version cannot receive the vulnerability's input (HTTP/2 streams) as it only supports HTTP/1.1, AJP, and WebSocket protocols."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8679b2e2-df62-56b7-9676-dcf240af1f8f",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13934 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2020-13934. The vulnerability requires HTTP/2 (h2c) protocol support to leak HTTP/1.1 processors during direct h2c connections. HTTP/2 support was first introduced in Tomcat 8.5/9.0 (circa 2016), and version 7.0.70 predates this feature entirely. The target codebase contains no HTTP/2 implementation, no h2c upgrade handling, and no UpgradeProtocol interface used by the vulnerable code pattern."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:17f356da-c1fc-52b3-8381-29e56e8966cd",
      "id": "CVE-2020-13935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13935 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7dff47b7-7423-514b-999f-89e944bb0998",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-13943 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. not_affected \u2014 The target repository (Apache Tomcat 7.0.70 at commit a78de4bfa3) does not contain HTTP/2 protocol support. CVE-2020-13943 affects the HTTP/2 implementation in the org.apache.coyote.http2 package, which does not exist in this version. HTTP/2 support was introduced in Tomcat 8.5.0+; version 7.0.70 only supports HTTP/1.1 and AJP protocols. The vulnerability's attack vector (HTTP/2 HEADERS frames ..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a60a800b-fdf6-51f5-85e9-8b482fd59c56",
      "id": "CVE-2020-1935",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-1935 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:29d50bdc-8181-5fda-8871-5eeea134cb83",
      "id": "CVE-2020-1938",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-1938 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02c3cff7-f98b-5ccd-9758-e46dd26a1aa8",
      "id": "CVE-2020-8022",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2020-8022 is a false positive for org.apache.tomcat:tomcat-i18n-ja 7.0.70-tuxcare.1."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09299a06-6187-544f-9209-fc1b764c0f12",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed725243-80a0-5c44-b3dd-7d342200211d",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:aa048ea6-e610-5bb9-b433-3cca9607efce",
      "id": "CVE-2021-25329",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-25329 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2142a559-1d13-5f4a-b737-0dea39175734",
      "id": "CVE-2021-30639",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-30639 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2021-30639. The vulnerability requires the errorException field in the org.apache.coyote.Request class, which does not exist in this version. This field was introduced in later versions (8.5.64, 9.0.44, 10.0.4) as part of non-blocking I/O error handling. The patches explicitly describe this as a \"regression introduced in [version]\", confirming the vulnerability was newly introduced in those specific versions and did not exist in earlier releases like 7.0.70."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3139901a-2cb9-52f8-ac1c-f8babe3ac94f",
      "id": "CVE-2021-30640",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-30640 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:68404903-441d-53cc-b44b-26bf8e60cec3",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-33037 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cadf38b8-23ea-5260-9a6e-8195f27c3642",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-42340 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is NOT affected by CVE-2021-42340. This vulnerability was introduced by BZ 63362 (metrics collection for HTTP upgrade connections) committed in October 2020, over 4 years after Tomcat 7.0.70 was released (June 2016). The leak-causing code (UpgradeInfo and UpgradeGroupInfo metrics objects that retain references to closed WebSocket connections) does not exist in version 7.0.70. The CVE's affected version ranges (8.5.60+, 9.0.40+, 10.0.0-M1+, 10.1.0-M1+) correctly exclude Tomcat 7.x because these versions predate the introduction of the vulnerable code path."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ae8bcbb6-3134-5d9c-b1dd-da8d8628ce41",
      "id": "CVE-2022-23181",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-23181 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. CVE-2022-23181 describes a Time-Of-Check-Time-Of-Use (TOCTOU) race condition introduced by the CVE-2020-9484 fix. This vulnerability pattern requires a path validation check that calls getCanonicalFile() for validation but returns a non-canonical file object, creating a race window. Version 7.0.70's FileStore.java file() method (lines 391-398) contains no path validation logic whatsoever - it simply creates and returns a File object without any canonical path checking. The specific TOCTOU code pattern is not present because the prerequisite check that creates the time-of-check point does not exist. The affected version ranges (9.0.35-9.0.56, 8.5.55-8.5.73, etc.) represent versions that received the CVE-2020-9484 fix but not the CVE-2022-23181 fix; 7.0.70 predates both fixes."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cad00b63-74bb-550f-abc6-e58fec94456d",
      "id": "CVE-2022-25762",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-25762 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c41a795-5003-5130-9fe0-05d06055693f",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-34305 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. not_affected \u2014 Apache Tomcat 7.0.70 is NOT AFFECTED by CVE-2022-34305. The vulnerability affects versions 8.5.50-8.5.81, 9.0.30-9.0.64, 10.0.0-10.0.22, and 10.1.0-10.1.0-M16, but NOT 7.0.x versions prior to 7.0.99. The vulnerable code paths (unfiltered display of session attributes and Principal attributes) do not exist in version 7.0.70. The session attribute display feature was added Nov 28, 2019 starting i..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4598b1d1-b5b5-5827-a3c2-28af9ece8335",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-42252 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fd315d9c-1aef-529b-bbf6-32c8776bd0f8",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-45143 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2022-45143. The vulnerable component JsonErrorReportValve does not exist in this version - it was introduced 4+ years later in Tomcat 9.0.40 (October 2020). Tomcat 7.0.70 only has ErrorReportValve, which outputs HTML error pages, not JSON. The attack chain requires JSON output to reach the Goal (manipulated JSON), but no JSON error reporting capability exists in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1734f89d-4d2b-591b-9542-389edd7b7af5",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:384fec8a-6acc-57a3-81e3-ed196e83f755",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-28708 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a1bca0-5d01-516d-8e20-4d3c9110d366",
      "id": "CVE-2023-28709",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28709 is fixed in version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:df84b72d-34ed-5a11-a7b2-da7e6dd68f78",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-41080 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:768d83be-c15f-59b2-b8a6-7495cd06a0b4",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e7d24b0d-7200-53f3-8c19-ceeaf96e78ed",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-45648 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bdeaab63-ec4b-5358-9de2-8486570b991e",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ed5425b1-41f9-529d-b158-0657f476cee7",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-24549 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2024-24549. This vulnerability is specific to HTTP/2 header processing in Apache Tomcat, where streams were not reset until after all headers (including CONTINUATION frames) were processed when limits were exceeded. HTTP/2 support was introduced in Tomcat 8.5.0, and version 7.0.70 predates this feature entirely. The target codebase contains only HTTP/1.1 and AJP protocol implementations, which already enforce header size limits incrementally during parsing, not after completion."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c640503c-2fb5-502d-9a03-7498db83ec3b",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38286 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a445ddae-ad16-572e-bc39-308e9d6c689d",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52316 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2024-52316. This vulnerability specifically affects Jakarta Authentication (JASPIC) ServerAuthContext exception handling, but JASPIC support does not exist in Tomcat 7.x. JASPIC was introduced in Tomcat 8.5.x, and the target version (7.0.70) predates this feature entirely. The vulnerable code pattern (authenticateJaspic method catching AuthException without setting HTTP status) cannot exist in this version."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c2ecc701-99a4-59a0-8be1-774dc594ab74",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:90a5659a-5e19-5611-82c7-8fb64162993e",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31650 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Apache Tomcat 7.0.70 is NOT affected by CVE-2025-31650. This vulnerability targets HTTP/2 priority header parsing code that does not exist in Tomcat 7.0.x. HTTP/2 support was added in Tomcat 8.5+. The target lacks all HTTP/2 infrastructure (no http2 package, no Priority parsing, no HTTP/2 upgrade handlers), so the vulnerable INPUT type (invalid HTTP/2 priority headers/frames) is never received by the target codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:850e0eda-4ebc-5357-a479-3a79076fcaa5",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-31651 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 does not contain the RewriteValve component where CVE-2025-31651 exists. The vulnerability requires RewriteValve to process rewrite rules with literal special characters ('%', ';', '?'). Without this component, the attack vector cannot exist. Exhaustive search confirms no RewriteValve.java, no rewrite directory under valves, and no URL rewriting functionality. RewriteValve was introduced in Tomcat 8.5+ series (CVE affects 8.5.0-8.5.100, 9.0.0-9.0.102, 10.1.0-10.1.39, 11.0.0-11.0.5)."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:26398dc6-72b7-5aa6-aaa2-e2b4ccd431d1",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46701 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:82b58ce6-e38e-5794-82b6-199eecde0bb3",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-48988 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eac0f2a2-dec1-5b3d-97dc-168099c3ed04",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-49125 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2025-49125. The vulnerability concerns the org.apache.catalina.webresources package (PreResources/PostResources features with insufficient path validation using startsWith without boundary checks), which was introduced in Tomcat 8.0 and does not exist in Tomcat 7.x. Tomcat 7 uses the org.apache.naming.resources DirContext architecture for resource management. While Tomcat 7 has analogous path-based resource mounting features (aliases in BaseDirContext and extraResourcePaths in VirtualDirContext), both implementations include proper boundary checks that prevent the vulnerability pattern described in the CVE."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:937aecf7-fe47-5662-b0af-59794e216c74",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4ae8d08b-195a-53f1-b2b1-13e7cba03fde",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-66614 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2025-66614. The vulnerability requires SNI (Server Name Indication) support to extract the TLS SNI hostname and SSLHostConfig-based per-virtual-host TLS configurations to enable different client certificate authentication requirements per virtual host. Tomcat 7.0.70 does not support SNI - this feature was introduced in Tomcat 8.5 (confirmed by the target's own documentation in ssl-howto.xml). The CVE explicitly states \"Older EOL versions are not affected\", and version 7.0.70 predates the 8.5.0 threshold. Code analysis confirms no SNI extraction code, no SSLHostConfig class, and no Java SNI APIs are present in 7.0.70."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:628c7b0a-cf94-5291-ad3f-c6b3e74ade38",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24733 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:27be5fa2-ec7b-5843-8617-4ad51a553eda",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:304e1bd9-aa50-59fb-a011-4eca09589548",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-29146 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Apache Tomcat 7.0.70 is not affected by CVE-2026-29146. The vulnerable EncryptInterceptor class does not exist in this version - it was introduced in Tomcat 7.0.100 or later. The CVE correctly identifies the affected version range starting at 7.0.100 for Tomcat 7.x. Target version 7.0.70 predates the vulnerable component."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9d6d7e0f-388c-5c42-829c-ecf3db4534e7",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32990 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. not_affected \u2014 Tomcat 7.0.70 is not affected by CVE-2026-32990. The vulnerability exists in the SNI (Server Name Indication) hostname validation code (checkSni method in AbstractEndpoint.java) which performs case-sensitive comparison when looking up SSL configurations. This SNI validation architecture, including the SSLHostConfig class and checkSni method, was introduced in Tomcat 8.5+ and does not exist in T..."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8c23dd81-9ffd-5970-bb17-82b93e01b191",
      "id": "CVE-2026-41284",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41284 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2794f586-21f0-532f-a2ac-41fe4f77c0c2",
      "id": "CVE-2026-41293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41293 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Tomcat 7.0.70 is not affected by CVE-2026-41293. The vulnerability concerns improper character validation in HTTP/2 HPACK header decoding. Tomcat 7.0.70 does not include HTTP/2 protocol support - it only supports HTTP/1.1 and AJP. HTTP/2 support was introduced in Tomcat 8.5 and later versions. The vulnerable code (HPackHuffman, HpackDecoder, Http2Parser classes and associated validation methods) is entirely absent from this version. Exhaustive search confirmed no http2 package, no HTTP/2 Java files, and no HTTP/2 protocol handlers exist in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:03d70349-2000-5bb1-8458-3752319336b7",
      "id": "CVE-2026-42498",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-42498 does not affect version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja. Apache Tomcat 7.0.70 is not affected by CVE-2026-42498. The vulnerability concerns exposure of HTTP authentication headers to unintended hosts during WebSocket client authentication. This version predates the introduction of WebSocket client authentication functionality, which was added between versions 7.0.82 and 7.0.83. The target lacks all authentication-related classes (Authenticator, BasicAuthenticator, DigestAuthenticator), authentication constants, and HTTP 401/407 response handling. Without the authentication feature, there are no authentication headers to expose."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8288b801-baa8-54d1-9d5b-00aa51b65158",
      "id": "CVE-2026-43512",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43512 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f753362-923c-5da9-a7bd-5ab8c563d8ba",
      "id": "CVE-2026-43513",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43513 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f2f7b4f-fc82-5b08-95e4-e96e03b8ca70",
      "id": "CVE-2026-43514",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43514 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d17dac27-6c17-57f4-a7f7-ff9cc1a2c15f",
      "id": "CVE-2026-43515",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-43515 affects version 7.0.70-tuxcare.1 of org.apache.tomcat:tomcat-i18n-ja."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-i18n-ja@7.0.70-tuxcare.1"
    }
  ]
}