Claim Missing Document
Check
Articles

Found 1 Documents
Search

Analisis Kerentanan Keamanan Sistem Enterprise Resource Planning Menggunakan PTES dan Owasp Zap Ekamartha, Ken Narendra; Wahanani, Henni Endah; Junaidi, Achmad
HORIZON: Indonesian Journal of Multidisciplinary Vol. 4 No. 4 (2026): HORIZON: Indonesian Journal of Multidisciplinary (In-Press)
Publisher : Lembaga Intelektual Muda (LIM) Maluku

Show Abstract | Download Original | Original Source | Check in Google Scholar | DOI: 10.54373/hijm.v4i4.7179

Abstract

This study aims to identify and analyze security vulnerabilities in the XYZ ERP system using the Penetration Testing Execution Standard (PTES) approach. The study was conducted through pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, and reporting, utilizing OWASP ZAP as the primary testing tool. Vulnerabilities were classified based on the Common Weakness Enumeration (CWE), while their severity was assessed using the Common Vulnerability Scoring System (CVSS) version 3.1. The study identified four main vulnerabilities: SQL Injection (CVSS 8.3; High), Brute Force Login Page (CVSS 8.2; High), Cross-Site Scripting (CVSS 5.4; Medium), and the risk of active session abuse (CVSS 4.2; Medium). These vulnerabilities have the potential to threaten data confidentiality, integrity, and availability through unauthorized access, data manipulation, account takeover, and user session abuse. This research provides technical recommendations for improving ERP system security and serves as a reference for organizations in systematically evaluating and mitigating web application vulnerabilities.