Skip to main content

Port Details

Port
7001
Transport
TCP
Service
WebLogic
IANA service name
afs3-callback
Range
User port (1024-49151)
Related ports
70025556

Security Exposure

Oracle WebLogic Server has several entries in the CISA KEV catalog. NVD describes CVE-2020-14882 (Console component) and CVE-2019-2725 (Web Services component) as easily exploitable by an unauthenticated attacker with network access via HTTP, with successful attacks resulting in takeover of the server.

Hardening

  • +Keep the Administration Server port off the internet and restrict it to administrator networks.
  • +Apply the Oracle security patches that fix the KEV-listed WebLogic vulnerabilities.
  • +Use the SSL listen port (7002 by default) for administration traffic.

Monitoring

Log access to the WebLogic Console and administrative actions, and alert on requests to WebLogic ports from untrusted networks.

WebLogic Vulnerabilities

14 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-21962
Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability
Oracle Corporation10.073.2%KEV2026-01-20
CVE-2024-21182
Oracle WebLogic Server Unspecified Vulnerability
Oracle Corporation7.574.2%KEV2024-07-16
CVE-2020-2883
Oracle WebLogic Server Unspecified Vulnerability
Oracle Corporation9.894.9%KEV2020-04-15
CVE-2020-14644
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation9.894.5%KEV2020-07-15
CVE-2017-3506
Oracle WebLogic Server OS Command Injection Vulnerability
Oracle Corporation7.496.3%KEV2017-04-24
CVE-2020-2551
Oracle Fusion Middleware Unspecified Vulnerability
Oracle Corporation9.893.2%KEV2020-01-15
CVE-2023-21839
Oracle WebLogic Server Unspecified Vulnerability
Oracle Corporation7.599.9%KEV2023-01-17
CVE-2018-2628
Oracle WebLogic Server Unspecified Vulnerability
Oracle Corporation9.8100.0%KEV2018-04-19
CVE-2017-10271
Oracle Corporation WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation7.5100.0%KEV2017-10-19
CVE-2019-2725
Oracle WebLogic Server, Injection
Oracle Corporation7.5100.0%KEV2019-04-26
CVE-2020-14882
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation9.8100.0%KEV2020-10-21
CVE-2020-14750
Oracle WebLogic Server Remote Code Execution Vulnerability
Oracle Corporation9.899.3%KEV2020-11-01
CVE-2020-14883
Oracle WebLogic Server Unspecified Vulnerability
Oracle Corporation7.297.9%KEV2020-10-21
CVE-2015-4852
Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability
-9.896.0%KEV2015-11-18

Tools for Auditing and Monitoring WebLogic

Nmap

Free / Commercial
Penetration Testing Tools

Network discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.

LicenseNPSL-0.95 (Nmap Public Source License, not OSI-approved)
PlatformLinux, macOS, Windows

Nuclei

Free / Commercial
Vulnerability Scanning

Fast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.

LicenseMIT
PlatformLinux, macOS, Windows

Nessus

Commercial
Vulnerability Scanning

Tenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.

LicenseProprietary
PlatformLinux, Windows, Web

Frequently Asked Questions

What is port 7001 used for?→

Oracle documents 7001 as the default listen port for the WebLogic Server Administration Server and 7002 as its SSL port.

Are WebLogic vulnerabilities exploited in the wild?→

Yes. CISA's Known Exploited Vulnerabilities catalog includes several WebLogic CVEs, among them CVE-2020-14882 and CVE-2019-2725.

Which vulnerabilities affect the service on port 7001?→

This database lists 14 CVEs related to WebLogic, 14 of them confirmed as exploited by CISA. Examples: CVE-2026-21962, CVE-2024-21182, CVE-2020-2883, CVE-2020-14644.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 7001 is not guaranteed to be WebLogic. Exploited-in-the-wild data from the CISA KEV catalog (CC0).