Analisis dan Evaluasi Risiko Kerentanan Aplikasi Web Berbasis OWASP WSTG dan CVSS
DOI:
https://doi.org/10.22441/format.2026.v15.i2.004Abstract
Meningkatnya ancaman terhadap aplikasi berbasis web mendorong perlunya evaluasi yang terstruktur terhadap keamanan aplikasi web perusahaan. Penelitian ini bertujuan untuk mengidentifikasi kerentanan, menilai tingkat risiko, serta menyusun rekomendasi perbaikan pada aplikasi web PT.XYZ menggunakan metodologi Open Web Application Security Project Web Security Testing Guide (OWASP WSTG) versi 4.2. Penelitian dilaksanakan menggunakan pendekatan Black Box Testing untuk menguji tiga kategori, yaitu Information Gathering, Configuration and Deployment Management Testing, dan Error Handling Testing, mengingat objek penelitian merupakan static company profile website tanpa form input maupun mekanisme otentikasi. Pengujian dilakukan menggunakan kombinasi tools seperti Whatweb, DNS recon, Fierce, Nmap, Nikto, WAFW00F, dan curl, dengan setiap temuan divalidasi secara manual untuk mengeliminasi false positive, sebelum dinilai tingkat risiko menggunakan Common Vulnerability Scoring System (CVSS) versi 3.1. Hasil pengujian dan validasi menunjukkan dua belas kerentanan yang tervalidasi, terdiri atas tiga kerentanan berkategori High dengan rentang skor 7,0 hingga 8,6, enam kerentanan berkategori Medium dengan rentang skor 4,0 hingga 5,9, dan dua kerentanan berkategori Low dengan rentang skor 2,6 hingga 3,1, tanpa ditemukan kerentanan berkategori Critical. Temuan dengan tingkat risiko tertinggi meliputii kondisi Dangling DNS pada subdomain yang mengarah ke infrastruktur pihak ketiga, penggunaan versi PHP yang telah mencapai status End-of-Life pada subdomain, serta eksposur layanan basis data yang dapat diakses dari jaringan publik. Sebanyak enam temuan berkorelasi dengan kategori A05:2021-Security Misconfiguration dan empat temuan dengan kategori A06:2021-Vulnerable and Outdated Components pada OWASP Top 10:2021, yang mengindikasikan bahwa kesalahan konfigurasi dan pemeliharaan komponen perangkat lunak merupakan sumber risiko dominan, dibandingkan dengan kerentanan pada logika aplikasi. Penelitian ini merekomendasikan pemutakhiran komponen perangkat lunak yang telah usang, pengetatan kontrol akses jaringan pada layanan basis data dan antarmuka administratif, serta pengelolaan siklus infrastruktur DNS secara berkala sebagai langkah mitigasi guna meningkatkan struktur keamanan aplikasi web secara berkelanjutan.
Downloads
References
[1] N. R. Jayanti, A. F. Sandy, and N. B. Anshary, “Pelatihan Desain dan Pengembangan Website Pada Yayasan Baitul Husna Harapan Indah,” Empowerment: J. Pengabdi. pada Masy., vol. 5, no. 1, pp. 41–48, 2025, [Online]. Available: HTTPS://www.journal.staidk.ac.id/index.PHP /pkm/article/view/972
[2] M. Fronita, “Analisis celah keamanan website Sitasi menggunakan vulnerability assessment,” J. Ilm. Rekayasa dan Manaj. Sist. …, 2023, [Online]. Available: HTTPS://ejournal.uin-suska.ac.id/index.PHP /RMSI/article/view/21823
[3] BSSN, “LANSKAP KEAMANAN SIBER INDONESIA 2024,” 2024, [Online]. Available: HTTPS://gate.bssn.go.id/ppid-document/Informasi-serta-merta/lanskap-keamanan-siber-indonesia/Lanskap Keamanan Siber Indonesia 2024.pdf
[4] idsirtii/cc, Laporan Bulanan Publik - Hasil Monitoring Keamanan Siber. 2025. [Online]. Available: HTTPS://drive.google.com/file/d/196vvBtvfyuz9rU-7CaZK0LSAi8B7vFRF/view
[5] Siaran Pers, “Kejahatan Siber Capai Kerugian Rp 476 M, AI Diperkuat untuk Cegah Ancaman di Ruang Digital,” KOMDIGI. Accessed: Feb. 12, 2026. [Online]. Available: HTTPS://www.komdigi.go.id/berita/siaran-pers/detail/kejahatan-siber-capai-kerugian-rp-476-m-ai-diperkuat-untuk-cegah-ancaman-di-ruang-digital
[6] OWASP Foundation, “OWASP Web Security Testing Guide v4.2,” OWASP WSTG. Accessed: Apr. 20, 2026. [Online]. Available: HTTPS://owasp.org/www-project-web-security-testing-guide/v42/2-Introduction/
[7] A. A. A. Setiawan, H. Farisi, and A. Suharsono, “Analisis Keamanan Aplikasi Web silapetro. ub. ac. id Menggunakan Metode VAPT dan WSTG 4.2,” … Teknol. Inf. dan Ilmu …, 2025, [Online]. Available: HTTPS://j-ptiik.ub.ac.id/index.PHP /j-ptiik/article/view/14901
[8] A. I. Rafeli, H. B. Seta, and I. W. Widi, “Pengujian Celah Keamanan Menggunakan Metode OWASP Web Security Testing Guide (WSTG) pada Website XYZ,” Inform. J. Ilmu Komput., vol. 18, no. 2, p. 97, 2022, doi: 10.52958/iftk.v18i2.4632.
[9] M. F. Yusuf, I. R. Hikmah, Amiruddin, and S. U. Sunaringtyas, “Security Testing of XYZ Website Application Using ISSAF and OWASP WSTG v4.2 Methods,” Teknika, vol. 14, no. 1, pp. 66–77, 2025, doi: 10.34148/teknika.v14i1.1156.
[10] D. F. Priambodo, A. D. Rifansyah, and M. Hasbi, “Penetration Testing Web XYZ Berdasarkan OWASP Risk Rating,” Teknika, 2023, [Online]. Available: HTTPS://ejournal.ikado.ac.id/index.PHP /teknika/article/view/571
[11] E. Setiawan and F. Fachri, “Pengujian dan Mitigasi Kerentanan Website Sistem Informasi Akademik Universitas Ma’arif Nahdlatul Ulama Kebumen dengan OWASP ZAP,” Cyber Secur. dan Forensik Digit., vol. 8, no. 1, pp. 25–33, 2025, doi: 10.14421/csecurity.2025.8.1.5190.
[12] B. N. Widyaningrum, D. Maya Rani, and L. Kurnia Ramadhani, “Analysis of the OWASP V4.2 Method in Hospital Information System Security Testing,” MEDIKA TRADA, vol. 5, no. 2, pp. 87–97, 2024, doi: 10.59485/jtemp.v5i2.99. [Online]. Available: HTTPS://journal.polbitrada.ac.id/index.PHP /Jtemp/article/view/99
[13] A. S. Lubis and M. P. A. Ginting, “Pengujian aplikasi berbasis web data SKA menggunakan metode Black Box Testing,” Cosm. J. Tek., 2024, [Online]. Available: HTTPS://journal.aira.or.id/cosmic/article/view/760
[14] I. UIN and A. S. P. Wijaya, “PROGRAM STUDI TEKNOLOGI INFORMASI FAKULTAS SAINS DAN TEKNOLOGI UNIVERSITAS ISLAM NEGERI WALISONGO SEMARANG,” eprints.walisongo.ac.id, [Online]. Available: HTTPS://eprints.walisongo.ac.id/29630/1/Skripsi_2008096010_Akbar_Sidiq_Putra_Wijaya.pdf
[15] FIRST, “Common Vulnerability Scoring System v3.1,” 2026, [Online]. Available: HTTPS://www.first.org/CVSS/v3.1/user-guide
[16] NIST-NVD, “Vulnerability Metrics”, [Online]. Available: HTTPS://nvd.nist.gov/vuln-metrics/CVSS
[17] M. A. Hakim, “Analisis Risiko Kerentanan Keamanan Aplikasi Gawai Layanan Masyarakat Pt. Xyz Menggunakan Parameter Owasp Mobile Security dan Pembobotan CVSS,” J. Sos. Teknol., 2025, [Online]. Available: HTTP://sostech.greenvest.co.id/index.PHP /sostech/article/view/32528
[18] D. Supriadi, E. Suryadi, R. Muslim, and ..., “Implementasi Vulnerability Assessment Owasp (Open Web Application Security Project) Pada Website Universitas Teknologi Mataram,” J. Data …, 2024, [Online]. Available: HTTPS://journal.ppmi.web.id/index.PHP /jdaics/article/view/1368
[19] OWASP Foundation, “OWASP Top 10:2021,” 2021, [Online]. Available: HTTPS://owasp.org/Top10/2021/id/
[20] I. M. A. Januraga, et al., “Mendeteksi Keamanan Website SMP Negeri 1 Blahbatuh Menggunakan Metode Open Web Application Security Project (OWASP) Versi 2.11: XSS & Rate Limiting,” Format: J. Ilm. Tek. Inform., vol. 11, no. 2, pp. 137–144, 2022.
[21] Alfian, et al., “Pencegahan Kerentanan Keamanan Jaringan Komputer Mikrotik Menggunakan Metode Penetration Testing,” J. Ilm. FIFO, vol. 16, no. 2, 2024, doi: 10.22441/fifo.2024.v16i2.003.
[22] Asih, et al., “Evaluasi Keamanan Data Pasien Pada Rekam Medis Elektronik Dengan Systematic Literature Review,” J. Ilm. FIFO.
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
The copyright to this article is transferred to Universitas Mercu Buana (UMB) if and when the article is accepted for publication. The undersigned hereby transfers any and all rights in and to the paper including without limitation all copyrights to UMB. The undersigned hereby represents and warrants that the paper is original and that he/she is the author of the paper, except for material that is clearly identified as to its original source, with permission notices from the copyright owners where required. The undersigned represents that he/she has the power and authority to make and execute this assignment.
We declare that this paper has not been published in the same form elsewhere.
Furthermore, I/We hereby transfer the unlimited rights of publication of the above-mentioned paper as a whole to UMB. The copyright transfer covers the right to reproduce and distribute the article, including reprints, translations, photographic reproductions, microform, electronic form (offline, online) or any other reproductions of similar nature.
The corresponding author signs for and accepts responsibility for releasing this material on behalf of any and all co-authors. This agreement is to be signed by at least one of the authors who have obtained the assent of the co-author(s) where applicable. After submission of this agreement signed by the corresponding author, changes of authorship or in the order of the authors listed will not be accepted.
Retained Rights/Terms and Conditions
Although authors are permitted to re-use all or portions of the Work in other works, this does not include granting third-party requests for reprinting, republishing, or other types of re-use.
Our Articles are licensed under CC BY-NC

This work is licensed under a Creative Commons Attribution-NonCommercial 4.0 International License.