The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Understanding Certainty Levels

Joel | Last updated: Aug 30, 2022 05:26PM UTC

Hello, I have been reviewed our vulnerabilities inside of our Burp Suite Enterprise instance and noticed the different certainty levels and researched their meaning but I had a question. There has been some cases where my scheduled scans will pick up a vulnerability and it will not be labeled "certain" but then the next week when the scan runs, the vulnerability will disappear. The following week, the same vulnerability shows up again at the same certainty level. I understand that this could be a potential false positive and would image that if it didn't come back on the following scan, it would be deemed a FP. But since it returned on a later scan, I was wondering about the logic behind the decision since there seems to be a continuous regression of the same vulnerability with no increase or decrease in certainty? Thank you for your help and clarification.

Alex, PortSwigger Agent | Last updated: Aug 31, 2022 08:08AM UTC

Hi Joel, Thanks for your post. Without understanding more about the application in question and the scan configuration in use, it would be difficult to comment on why this particular vulnerability appears on some scans and not others. It’s possible that the state of the application during the scan is the reason, i.e. it may not react in the same way between each and every audit, for example, if a particular location becomes unresponsive during the scan. The scan configuration used would typically determine how this is handled, and there may be some scan configuration options that would assist in your scenario. We would be happy to review any scan results and/or scan logs between your scans to assist further, you can submit these to support@portswigger.net and we shall take a look. Best regards,

Astroluna.xyz | Last updated: Aug 31, 2022 03:32PM UTC