Photo Gallery
![]() |
ERPScan

Additional Info
Job title of nominated professional (or team name) | CTO |
Company (where nominated professional or team is working) | ERPScan |
Website | https://erpscan.com |
Company size (employees) | 60 |
Country | United States |
Overview
Our research team continuously innovating and always on the edge of technologies. They started their research in SAP security even before
Overall Leadership:
– Reveal 3 most critical issues in SAP
– Leaders by the number of founded vulnerabilities in SAP and Oracle (400+ 0-days found)
– 80+ Innovative Presentations in security conference in 25 countries
– Award-winning research papers “SAP Security in figures”
– 15 research whitepapers
– 2nd Place on Top Web Hacking Techniques 2012
Innovation:
• 2007 reported vulnerabilities in SAP and Oracle;
• 2008 Acknowledged for vulnerabilities in SAP and Oracle;
• 2009 World-first public presentation about SAP Frontend security;
• 2010 World-first public presentation include attacks on Oracle JDE;
• 2010 reported World-first vulnerabilities in SAP BusnessObjects;
• 2011 World-first public presentation about SAP J2EE security;
• 2011 World-first product to analyze SAP J2EE Platform security;
• 2012 World-First public presentation about Oracle Peoplesoft attacks;
• 2013 World-first Product to combine vulnerability, Code and SOD checks in one platform;
• 2013 Invented new type of attack against SAP and other applications– SSRF;
• 2013 World-first vulnerabilities published in SAP Mobile applications;
• 2014 World-first Training about Business Application Security;
• 2015 World-first product to analyze Oracle Peoplesoft Platform security;
• 2015 World-first public presentation about SAP Mobile Platform security
• 2015 Innovative presentation about Oil and Gas Cybersecurity
• 2016 Identified vulnerabilities in Manufacturing software
Accomplishments
- ERPScan Researchers It has achieved multiple acknowledgments from the largest software vendors like SAP, Oracle, Microsoft, IBM, VMware, HP for finding 400+ vulnerabilities in their products. ERPScan researchers take proud in exposing new types of vulnerabilities (TOP 10 Web hacking techniques 2012) and were nominated for best server-side vulnerability in BlackHat 2013.
- ERPScan experts have been invited to speak, present and train at 80+ prime international security conferences in 25+ countries across the continents. These include BlackHat, RSA, HITB as well as private trainings for Fortune 2000 companies and Military. Experts were mentioned in Wired, VICE, BusinessInsider, Reuters, The Register, and other media sources in 20+ countries for their research.
- ERPScan researchers lead non-profit project EAS-SEC, which is focused on enterprise application security research and awareness. They have published 3 exhaustive annual award-winning surveys about SAP Security.