Burp Suite User Forum

Create new post

Is is safe to remove old versions of JRE from Burpsuite Enterprise?

Ken | Last updated: Sep 28, 2021 10:40AM UTC

Hi, Burp Suite Enterprise Edition : Version: 2021.8.1-7685 Noticed today that a Nessus scan of our linux based Burpsuite Enterprise is warning about out of date Java The following Java JRE installations are unsupported : Path : /usr/local/burpsuite_enterprise Installed version : 1.9.0_4 Latest versions : 1.8.x / 1.11.x / 1.15.x Support dates : 2018-03-01 (end of life) Path : /usr/local/burpsuite_enterprise/jres/9.0.4 Installed version : 1.9.0_4 Latest versions : 1.8.x / 1.11.x / 1.15.x Support dates : 2018-03-01 (end of life) When I checked the installed location I can see v9.0.4 and v11.0.10.9.1. ~$ ll /usr/local/burpsuite_enterprise/jres/ total 8 drwxr-sr-x 7 burpsuite burpsuite 4096 Jun 26 02:00 11.0.10.9.1 drwxr-sr-x 7 burpsuite burpsuite 4096 Jul 18 2019 9.0.4 Can I just delete the 9.0.4 directory? It doesn't appear to be being used to run Burpsuite Enterprise ps aux | grep java burpsui+ 1189 0.1 1.3 7608464 223376 ? Sl Sep22 10:26 /usr/local/burpsuite_enterprise/jre/bin/java -Dinstall4j.jvmDir=/usr/local/burpsuite_enterprise/jre -Dexe4j.moduleName=/usr/local/burpsuite_enterprise/burpsuiteenterpriseedition_webserver -Dinstall4j.launcherId=192 -Dinstall4j.swt=false -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4j.vpt=true -classpath /usr/local/burpsuite_enterprise/.install4j/i4jruntime.jar:/usr/local/burpsuite_enterprise/supervisor/supervisor-1.1-2016.jar com.install4j.runtime.launcher.UnixLauncher start 2ff15a18 ${installer:logsDirectory}/supervisor_webServer.log+ ${installer:logsDirectory}/supervisor_webServer.log+ net.portswigger.Supervisor webServer/.supervise burpsui+ 1199 0.1 1.3 7608464 226116 ? Sl Sep22 10:24 /usr/local/burpsuite_enterprise/jre/bin/java -Dinstall4j.jvmDir=/usr/local/burpsuite_enterprise/jre -Dexe4j.moduleName=/usr/local/burpsuite_enterprise/burpsuiteenterpriseedition_agent -Dinstall4j.launcherId=195 -Dinstall4j.swt=false -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4j.vpt=true -classpath /usr/local/burpsuite_enterprise/.install4j/i4jruntime.jar:/usr/local/burpsuite_enterprise/supervisor/supervisor-1.1-2016.jar com.install4j.runtime.launcher.UnixLauncher start 7048aa1a ${installer:logsDirectory}/supervisor_enterpriseAgent.log+ ${installer:logsDirectory}/supervisor_enterpriseAgent.log+ net.portswigger.Supervisor enterpriseAgent/.supervise burpsui+ 1204 1.2 2.7 7830572 457372 ? Sl Sep22 106:42 /usr/local/burpsuite_enterprise/jre/bin/java -Dinstall4j.jvmDir=/usr/local/burpsuite_enterprise/jre -Dexe4j.moduleName=/usr/local/burpsuite_enterprise/burpsuiteenterpriseedition_db -Dh2.bindAddress=0.0.0.0-Dinstall4j.launcherId=156 -Dinstall4j.swt=false -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4j.vpt=true -classpath /usr/local/burpsuite_enterprise/.install4j/i4jruntime.jar:/usr/local/burpsuite_enterprise/database/h2-1.4.197.jar com.install4j.runtime.launcher.UnixLauncher start 616e056a /usr/local/burpsuite_enterprise/error.log+ /usr/local/burpsuite_enterprise/output.log+ org.h2.tools.Server -tcp -ifExists -tcpPort 9092 -tcpAllowOthers -baseDir ${installer:dataDirectory}/data burpsui+ 1211 0.1 1.3 7608464 222564 ? Sl Sep22 10:23 /usr/local/burpsuite_enterprise/jre/bin/java -Dinstall4j.jvmDir=/usr/local/burpsuite_enterprise/jre -Dexe4j.moduleName=/usr/local/burpsuite_enterprise/burpsuiteenterpriseedition_enterpriseserver -Dinstall4j.launcherId=193 -Dinstall4j.swt=false -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4jv=0 -Di4j.vpt=true -classpath /usr/local/burpsuite_enterprise/.install4j/i4jruntime.jar:/usr/local/burpsuite_enterprise/supervisor/supervisor-1.1-2016.jar com.install4j.runtime.launcher.UnixLauncher start ed14aa48 ${installer:logsDirectory}/supervisor_enterpriseServer.log+ ${installer:logsDirectory}/supervisor_enterpriseServer.log+ net.portswigger.Supervisor enterpriseServer/.supervise burpsui+ 1310 0.2 4.3 8050748 711184 ? Sl Sep22 22:24 /usr/local/burpsuite_enterprise/jres/11.0.10.9.1/bin/java -cp lib/* -Dlogback.configurationFile=web-logback.xml -DlogsDirectory=/var/log/BurpSuiteEnterpriseEdition -Djava.security.egd=file:///dev/urandom net.portswigger.enterprise.web.StartWebServer burpsui+ 1311 0.2 2.6 7883696 438072 ? Sl Sep22 17:37 /usr/local/burpsuite_enterprise/jres/11.0.10.9.1/bin/java -cp lib/* -Dlogback.configurationFile=agent-logback.xml -DlogsDirectory=/var/log/BurpSuiteEnterpriseEdition -Djava.security.egd=file:///dev/urandomnet.portswigger.enterprise.agent.StartAgent burpsui+ 1492 0.4 3.8 7940040 624704 ? Sl Sep22 33:45 /usr/local/burpsuite_enterprise/jres/11.0.10.9.1/bin/java -cp lib/* -Dlogback.configurationFile=server-logback.xml -DlogsDirectory=/var/log/BurpSuiteEnterpriseEdition -Djava.security.egd=file:///dev/urandom net.portswigger.enterprise.server.StartEnterpriseServer burpsui+ 1661 0.5 1.3 7868184 222824 ? Sl Sep22 49:19 /usr/local/burpsuite_enterprise/jres/11.0.10.9.1/bin/java -Djava.awt.headless=true -Djdk.http.auth.tunneling.disabledSchemes= --add-opens java.base/javax.crypto=ALL-UNNAMED --add-opens java.base/java.lang.reflect=ALL-UNNAMED --add-opens java.base/java.lang=ALL-UNNAMED --add-opens java.desktop/javax.swing=ALL-UNNAMED -Djava.util.prefs.userRoot=/var/lib/BurpSuiteEnterpriseEdition/.BurpSuiteEnterprise/enterprise-server -cp /usr/local/burpsuite_enterprise/burp/burpsuite_pro_v2021.8.3.jar burp.StartBurp --i-accept-the-license-agreement --execution-mode=enterprise-server --user-config-file=/tmp/burp_14123989554664256714.config nimda 26436 0.0 0.0 6208 892 pts/0 S+ 11:38 0:00 grep --color=auto java Cheers Steve

Alex, PortSwigger Agent | Last updated: Sep 28, 2021 02:54PM UTC

Hi Ken, Thanks for your post. Please ensure you don't delete for the time being, whilst not used by the web app, Java 9 is still present as it performs a minor supervisor role to monitor and restart some services. We are currently in the process of releasing an update that will clean up old versions of Java from your install, I've added this thread to the tracker and will update accordingly. Thanks

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.