{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:ed4b6fa7-3194-5d4b-b03f-ea696d24bf6c",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10",
      "type": "library",
      "group": "org.springframework.boot",
      "name": "spring-boot-starter-activemq",
      "version": "2.4.6-tuxcare.10",
      "purl": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:2d5eeee0-2ba1-515a-8a8e-76b2da862b0f",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eaa3b7b0-ceff-5196-a1bc-3462cbad49f0",
      "id": "CVE-2023-20873",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20873 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:473681d7-4ae8-55a2-96e0-d65fb897ae32",
      "id": "CVE-2023-20883",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20883 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c0df6317-63ef-5d30-a2d4-300e85a39c9a",
      "id": "CVE-2023-34055",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-34055 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e28be483-d224-5993-abea-6f0fe18e92cd",
      "id": "CVE-2023-38286",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-38286 affects version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d504b6d1-8904-5c6a-a1e0-bed7d5e3a7ae",
      "id": "CVE-2024-38807",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38807 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7591b4fc-b59d-56e2-a0f4-702bfca7a653",
      "id": "CVE-2025-22235",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22235 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eda72dcb-ff03-5049-8ec5-dcc45bbe581e",
      "id": "CVE-2026-22733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22733 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0711ef55-28df-5e71-83a1-2f710fe3d432",
      "id": "CVE-2026-40972",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40972 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8748bdf-382f-55ae-925f-3884179d4216",
      "id": "CVE-2026-40973",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40973 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19f69362-26f3-511d-bc68-202565a5dd25",
      "id": "CVE-2026-40974",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40974 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f0fc30f9-2e78-54ad-bea6-0b4e13917fa1",
      "id": "CVE-2026-40975",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40975 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:802d37f9-1fc0-5444-9c93-bc275cf956bc",
      "id": "CVE-2026-40977",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-40977 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af50c915-eeca-5160-bcd3-048271a8f4c4",
      "id": "CVE-2026-40992",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-40992 does not affect version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq. version is out of affected scope 3.4.0 - 3.4.16, 3.5.0 - 3.5.14, 4.0.0 - 4.0.6; MailProperties has no Ssl class and the mail autoconfigure package has zero ssl references, so the vulnerable mail SSL auto-config code path is not present"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12ce0d7d-eeb9-59b9-9ba9-858b8f07f29b",
      "id": "CVE-2026-41001",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41001 is fixed in version 2.4.6-tuxcare.10 of org.springframework.boot:spring-boot-starter-activemq."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework.boot/spring-boot-starter-activemq@2.4.6-tuxcare.10"
    }
  ]
}