Analisis Kerentanan Keamanan Sistem Enterprise Resource Planning Menggunakan PTES dan Owasp Zap
Main Article Content
Abstract
This study aims to identify and analyze security vulnerabilities in the XYZ ERP system using the Penetration Testing Execution Standard (PTES) approach. The study was conducted through pre-engagement interactions, intelligence gathering, threat modeling, vulnerability analysis, exploitation, and reporting, utilizing OWASP ZAP as the primary testing tool. Vulnerabilities were classified based on the Common Weakness Enumeration (CWE), while their severity was assessed using the Common Vulnerability Scoring System (CVSS) version 3.1. The study identified four main vulnerabilities: SQL Injection (CVSS 8.3; High), Brute Force Login Page (CVSS 8.2; High), Cross-Site Scripting (CVSS 5.4; Medium), and the risk of active session abuse (CVSS 4.2; Medium). These vulnerabilities have the potential to threaten data confidentiality, integrity, and availability through unauthorized access, data manipulation, account takeover, and user session abuse. This research provides technical recommendations for improving ERP system security and serves as a reference for organizations in systematically evaluating and mitigating web application vulnerabilities.