Burp Suite User Forum

Create new post

java version with burp enterprise

scott | Last updated: Oct 16, 2019 04:08AM UTC

How do I upgrade the vulnerable java 9 version bundled with Burp Enterprise?

Mike, PortSwigger Agent | Last updated: Oct 16, 2019 08:28AM UTC

Hi Scott, Unfortunately, we don't have a mechanism to update the JRE bundled with Enterprise. Do you have any documentation about these vulnerabilities?

Burp User | Last updated: Oct 17, 2019 06:32PM UTC

Java9 is EOL as of march 2018, and therefore not being evaluated for security vulnerabilities. http://www.oracle.com/technetwork/java/eol-135779.html This is a security tool that I cannot run in my secure environment due to it running a non-compliant version of java.

Liam, PortSwigger Agent | Last updated: Oct 18, 2019 07:42AM UTC

Hi Scott We're currently reviewing your issue. We'll get back to you when we have something to share.

Liam, PortSwigger Agent | Last updated: Oct 22, 2019 02:46PM UTC

We are planning to upgrade the embedded Java version before long, unfortunately, we can't provide an ETA. Although Java 9 is no longer supported, we have reviewed the security issues that have been raised since the last release. These are mostly not relevant to server applications, and only affect applets running in the browser, etc. A remaining few issues are denial of service issues in the image decoding libraries which are not used in Enterprise. Our assessment is that there is currently not a significant risk in remaining on Java 9, but we will continue to monitor the situation.

Fernandez, | Last updated: Jul 13, 2020 04:39PM UTC

Hello, any update on this?

Liam, PortSwigger Agent | Last updated: Jul 14, 2020 09:48AM UTC

This update is planned during the Q4 of this year. We'll update you when this is released. Thanks for your patience.

Philip | Last updated: Feb 01, 2021 01:01PM UTC

any update to this, Q1/next release 2021?

Liam, PortSwigger Agent | Last updated: Feb 02, 2021 08:35AM UTC

We'll get back to you with an update ASAP.

Liam, PortSwigger Agent | Last updated: Feb 04, 2021 01:20PM UTC

Unfortunately, we don't have a release date for this update. We are still working on this. We'll update this thread when we have something to share.

Liam, PortSwigger Agent | Last updated: Feb 10, 2021 01:03PM UTC

We are planning to upgrade the embedded Java version before long, unfortunately, we cannot provide an ETA for this.     Although Java 9 is no longer supported, we have reviewed the security issues that have been raised since the last release. These are mostly not relevant to server applications, and only affect applets running in the browser, etc. There is a denial of service issue in the image decoding libraries, however, these are not used in Enterprise. Our assessment is that there is currently not a significant risk in remaining on Java 9, but we will continue to monitor the situation.

Brian | Last updated: May 17, 2021 05:35PM UTC

Any progress in moving to a supported version of Java?

Liam, PortSwigger Agent | Last updated: May 18, 2021 07:41AM UTC

We're still working on this update. We'll update this thread when we are ready to release.

Brian | Last updated: Jun 07, 2021 03:30PM UTC

Is it possible to get an ETA for this fix?

Liam, PortSwigger Agent | Last updated: Jun 08, 2021 10:32AM UTC

Hi Brian We'll be updating to Java 11 in the next release.

Steve | Last updated: Jan 25, 2022 10:21PM UTC

Any update to this? A scan shows Java 9 still present.

Liam, PortSwigger Agent | Last updated: Jan 26, 2022 10:18AM UTC

Which version of BSEE are you running? It should be updated to 11. There might be some Java 9 folders that the scan is picking up. If you run the installer again, this should clear them out.

Ted | Last updated: Mar 17, 2022 05:26PM UTC

It isn't a matter of just the Java 9 binaries still being in place, based on what I am seeing on our server there are active processes using both Java 9 and Java 11. However Java 9 has been out of support since January 2018 and we cannot continue to use it. How can we switch all processes to use Java 11?

Liam, PortSwigger Agent | Last updated: Mar 18, 2022 11:18AM UTC

Hi Ted. Thanks for your message. The active processes are part of the (supervisor) update mechanism. If you run the uninstaller again, this issue should be resoved. Apologies for the inconvenience.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.