Port 7001: Oracle WebLogic Server listen port
Port 7001 is the default listen port of the Oracle WebLogic Server Administration Server, with 7002 as the default SSL listen port. Oracle assigns ports sequentially, so a second Administration Server gets 7002. IANA assigns 7001 to afs3-callback, which differs from this common use.
Port Details
Security Exposure
Oracle WebLogic Server has several entries in the CISA KEV catalog. NVD describes CVE-2020-14882 (Console component) and CVE-2019-2725 (Web Services component) as easily exploitable by an unauthenticated attacker with network access via HTTP, with successful attacks resulting in takeover of the server.
Hardening
- +Keep the Administration Server port off the internet and restrict it to administrator networks.
- +Apply the Oracle security patches that fix the KEV-listed WebLogic vulnerabilities.
- +Use the SSL listen port (7002 by default) for administration traffic.
Monitoring
Log access to the WebLogic Console and administrative actions, and alert on requests to WebLogic ports from untrusted networks.
WebLogic Vulnerabilities
14 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | Oracle Corporation | 10.0 | 73.2% | KEV | 2026-01-20 |
| CVE-2024-21182 | Oracle WebLogic Server Unspecified Vulnerability | Oracle Corporation | 7.5 | 74.2% | KEV | 2024-07-16 |
| CVE-2020-2883 | Oracle WebLogic Server Unspecified Vulnerability | Oracle Corporation | 9.8 | 94.9% | KEV | 2020-04-15 |
| CVE-2020-14644 | Oracle WebLogic Server Remote Code Execution Vulnerability | Oracle Corporation | 9.8 | 94.5% | KEV | 2020-07-15 |
| CVE-2017-3506 | Oracle WebLogic Server OS Command Injection Vulnerability | Oracle Corporation | 7.4 | 96.3% | KEV | 2017-04-24 |
| CVE-2020-2551 | Oracle Fusion Middleware Unspecified Vulnerability | Oracle Corporation | 9.8 | 93.2% | KEV | 2020-01-15 |
| CVE-2023-21839 | Oracle WebLogic Server Unspecified Vulnerability | Oracle Corporation | 7.5 | 99.9% | KEV | 2023-01-17 |
| CVE-2018-2628 | Oracle WebLogic Server Unspecified Vulnerability | Oracle Corporation | 9.8 | 100.0% | KEV | 2018-04-19 |
| CVE-2017-10271 | Oracle Corporation WebLogic Server Remote Code Execution Vulnerability | Oracle Corporation | 7.5 | 100.0% | KEV | 2017-10-19 |
| CVE-2019-2725 | Oracle WebLogic Server, Injection | Oracle Corporation | 7.5 | 100.0% | KEV | 2019-04-26 |
| CVE-2020-14882 | Oracle WebLogic Server Remote Code Execution Vulnerability | Oracle Corporation | 9.8 | 100.0% | KEV | 2020-10-21 |
| CVE-2020-14750 | Oracle WebLogic Server Remote Code Execution Vulnerability | Oracle Corporation | 9.8 | 99.3% | KEV | 2020-11-01 |
| CVE-2020-14883 | Oracle WebLogic Server Unspecified Vulnerability | Oracle Corporation | 7.2 | 97.9% | KEV | 2020-10-21 |
| CVE-2015-4852 | Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability | - | 9.8 | 96.0% | KEV | 2015-11-18 |
Tools for Auditing and Monitoring WebLogic
Nmap
Free / CommercialNetwork discovery scanner and port auditor for discovering live hosts, open ports, running services, and OS fingerprints.
Nuclei
Free / CommercialFast vulnerability scanner powered by community YAML templates to scan web applications, networks, and cloud targets for known defects.
Nessus
CommercialTenable vulnerability scanner with the industry’s largest plugin library; time-limited free Essentials license.
Related Tool Categories
Static source analysis, dynamic scanners, and dependency vulnerability checkers.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
Infrastructure scanners, CVE audit engines, container image inspectors, and exposure management platforms.
Frequently Asked Questions
What is port 7001 used for?→
Oracle documents 7001 as the default listen port for the WebLogic Server Administration Server and 7002 as its SSL port.
Are WebLogic vulnerabilities exploited in the wild?→
Yes. CISA's Known Exploited Vulnerabilities catalog includes several WebLogic CVEs, among them CVE-2020-14882 and CVE-2019-2725.
Which vulnerabilities affect the service on port 7001?→
This database lists 14 CVEs related to WebLogic, 14 of them confirmed as exploited by CISA. Examples: CVE-2026-21962, CVE-2024-21182, CVE-2020-2883, CVE-2020-14644.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 7001 is not guaranteed to be WebLogic. Exploited-in-the-wild data from the CISA KEV catalog (CC0).