The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp Profession Scan missing HIGH Severity Issue

sania | Last updated: Jan 20, 2020 12:27PM UTC

Hi, I have scanned same application in Burp Professional v2 and Burp Enterprise Edition v1.0.15beta but as per the reports Burp Pro is missing in HIGH Severity i.e. SQL issue in report whereas Enterprise Report is showing the SQL issue in the application. what could be the reason? kindly suggest to fix it this issue.

Hannah, PortSwigger Agent | Last updated: Jan 20, 2020 02:58PM UTC

We would suggest using the most up-to-date version of both Enterprise and Professional (v2020.1 and v2.1.07 respectively) and using the default scan configuration on both, in order to compare the two. Burp Suite Professional and Enterprise both use the same Scanner, so there shouldn't be any difference between the two results when you are using the same Scanner version.

Burp User | Last updated: Jan 21, 2020 10:11AM UTC

currently i am using the Burp Enterprise Version: 2020.1-2902, Java version: 9.0.4 and Burp Professional v2.1.04. where I am not getting the same result. Do I need to use Burp Extension jar file to get the same reports ? or reports are matching because of the version issue. And even I have observed that Enterprise is take only seconds to complete the Scan and Professional is taking 5 to 10 m for the same application and reports are not matching.

Hannah, PortSwigger Agent | Last updated: Jan 21, 2020 10:12AM UTC

There have been a few significant changes to the scanner since 2.1.04, so we advise updating your Professional version to 2.1.07. In order to compare the two, you would need to disable all extensions on Burp Professional, use the same scan configuration and use the most up to date versions of each. With regard to the time difference between the two, how many agents do you have for Enterprise? Are you seeing a similar number of requests and locations between the two products for the same scan?

Burp User | Last updated: Jan 27, 2020 02:44PM UTC

Could you let me know the major difference between Burp Pro and Enterprise tool. Its limitations and similarity.

Ben, PortSwigger Agent | Last updated: Jan 27, 2020 02:53PM UTC