Burp Suite User Forum

Create new post

Question about serialNumber field in the XML report

Rundale | Last updated: Dec 05, 2023 11:15PM UTC

Hi, I have some questions after looking at serial numbers from multiple reports that ran using different project files but scanned the same application. There are duplicate serial numbers in these reports. How does Burp generate this serial number for each finding? Does the serial number track reoccurring vulnerability?

Michelle, PortSwigger Agent | Last updated: Dec 06, 2023 12:00PM UTC

For a given instance of Burp, the serial number in the XML output is a unique identifier. If you generate XML output on several occasions as issues are accumulated, then the serial number should be the same for the same issues in each export if you use the same instance of Burp. If you scan the same issue again with a different instance of Burp, the issue will be reported with a different serial number.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.