{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:2f053499-1b28-5c00-8bad-64ad8b87cc44",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5",
      "type": "library",
      "group": "org.apache.tomcat",
      "name": "tomcat-storeconfig",
      "version": "9.0.46-tuxcare.5",
      "purl": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:02939df7-e0c6-57d4-89a8-0501c660468e",
      "id": "CVE-2020-11996",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-11996 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:bd1bf1f0-3ac6-579d-a01f-6e4eeba83f83",
      "id": "CVE-2020-13934",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13934 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60217900-5b60-5594-9967-a0574e28e8e4",
      "id": "CVE-2020-13943",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-13943 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:12981715-49f9-5e26-aa6b-c9b3be6a7524",
      "id": "CVE-2020-9484",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-9484 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:73c2ff11-9d82-589d-a5d3-7bee52ea49ec",
      "id": "CVE-2021-24122",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-24122 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:eb86c4bc-68b5-53e8-b6cf-93864b3319ef",
      "id": "CVE-2021-33037",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-33037 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:baee21f3-e115-5e63-bea0-f9916c632306",
      "id": "CVE-2021-42340",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-42340 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d8b008dc-60fd-57a1-97c9-ae844ac5f903",
      "id": "CVE-2021-43980",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-43980 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0946bc11-98da-5b63-a5d0-148d2d97dcc0",
      "id": "CVE-2022-29885",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-29885 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d6971bcc-2bb2-5c75-905d-9a2254f15946",
      "id": "CVE-2022-34305",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-34305 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:341738fe-b33b-5958-96fd-57ecbd3ab8cd",
      "id": "CVE-2022-42252",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-42252 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c346ce2-06e2-584b-aa64-ec72575cd9e3",
      "id": "CVE-2022-45143",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-45143 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ff3d8068-3e2a-53f0-9050-d4922a49d1c3",
      "id": "CVE-2023-24998",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-24998 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:563d7de3-66cd-5916-b4ea-b4fd87b4fcd8",
      "id": "CVE-2023-28708",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-28708 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a6ec1f2c-5c32-5b0b-a67e-f0551a799687",
      "id": "CVE-2023-41080",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-41080 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af9b1bc7-7509-57a0-a877-4d7f901eeabb",
      "id": "CVE-2023-42795",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-42795 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3998c487-e1d6-5bac-8530-a203b93a7fda",
      "id": "CVE-2023-44487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-44487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c011cef4-ce39-55f7-837a-674d208e695d",
      "id": "CVE-2023-45648",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-45648 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:99c7c781-df11-5052-8309-d08bda2020d3",
      "id": "CVE-2023-46589",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-46589 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:dc0bf9a4-0d2a-565e-a349-a8bc16d2d2ed",
      "id": "CVE-2024-23672",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-23672 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c4312a80-92eb-5c04-9fda-770b352ddcaf",
      "id": "CVE-2024-24549",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-24549 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6edfb869-cc5e-5217-ad4c-986a150a708c",
      "id": "CVE-2024-34750",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-34750 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a4fbc9d3-cb78-58c1-99c1-57c46f36068b",
      "id": "CVE-2024-38286",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38286 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:81a391bd-62ce-555d-be4b-5a17a4b5d144",
      "id": "CVE-2024-50379",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-50379 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:14465343-92e5-5951-b6eb-96887080b558",
      "id": "CVE-2024-52316",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52316 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:24de4639-0673-562c-8050-6f82120b316e",
      "id": "CVE-2024-54677",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-54677 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e366d3a-0db7-5d19-945e-5eae38f34cd1",
      "id": "CVE-2024-56337",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-56337 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c0718eb-2837-5be2-9725-61e6f205d7f0",
      "id": "CVE-2025-24813",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-24813 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:79463d53-2669-50dd-9d34-eecaab201d50",
      "id": "CVE-2025-31650",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-31650 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:734c680c-7c19-5776-83d7-017f028b5d6f",
      "id": "CVE-2025-31651",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-31651 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5f29d6b6-e508-5f14-bc14-f1a137deb678",
      "id": "CVE-2025-46701",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-46701 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c22fdd80-51ef-55a7-bafe-4f259a395b71",
      "id": "CVE-2025-48988",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48988 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:19234062-bd0e-541a-ac6f-87288573e048",
      "id": "CVE-2025-48989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-48989 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:af57cf19-544e-5f1f-a315-addc1bbd06f7",
      "id": "CVE-2025-49124",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49124 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3524a84a-c19b-56ed-aa23-914315520dea",
      "id": "CVE-2025-49125",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-49125 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:05a0d4f1-106a-5675-a3c9-83eefa96cfce",
      "id": "CVE-2025-52434",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-52434 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5230e06b-869e-5ae7-a176-bc647b9a1dfa",
      "id": "CVE-2025-52520",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-52520 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:92a3822a-f12e-56e3-982c-e9ac6ae1cfd0",
      "id": "CVE-2025-53506",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-53506 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1c61731b-b146-5906-9391-a90fddcc061b",
      "id": "CVE-2025-55668",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55668 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da43c603-baaa-5688-88a7-ee71544402b7",
      "id": "CVE-2025-55752",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55752 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b013bdd-a397-5802-b25d-23c0a3d5010b",
      "id": "CVE-2025-55754",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-55754 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fe988483-be32-5d26-bf0b-11654fdafd81",
      "id": "CVE-2025-61795",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-61795 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:59c5e645-0197-5bbc-999c-7b42b55a3a7e",
      "id": "CVE-2025-66614",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-66614 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b15e3432-171b-55ff-98c9-5cf8ca287fe1",
      "id": "CVE-2026-24733",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-24733 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a1efb276-28f2-5396-b049-eb7fe571225c",
      "id": "CVE-2026-24880",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-24880 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b94ecbaf-fa0b-5fcd-afb0-7c363b81f6f0",
      "id": "CVE-2026-25854",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25854 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a106e521-70a0-545c-92f4-528c128628a8",
      "id": "CVE-2026-29146",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29146 is fixed in version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5b2f7c1b-bd40-577f-9b51-c672cec95a32",
      "id": "CVE-2026-32990",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32990 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e709daf-a154-5d0d-851c-d21d84a52064",
      "id": "CVE-2026-34483",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34483 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56d99afe-a2eb-5b43-8686-3bc22dd8e9c1",
      "id": "CVE-2026-34486",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34486 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:07d00360-25a2-5db5-8262-9e197c71e43b",
      "id": "CVE-2026-34487",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-34487 affects version 9.0.46-tuxcare.5 of org.apache.tomcat:tomcat-storeconfig."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.apache.tomcat/tomcat-storeconfig@9.0.46-tuxcare.5"
    }
  ]
}