3,331,906 on Port 7001 and 1,037,743 on Port 7199: Java Middleware and Its Management Ports
Two ports in the Java application ecosystem, both measurable in the millions, and both historically associated with remote code execution reachable without credentials.
The measurement
Two queries ran on 25 September 2026 with sub_type=all and pagesize 1. The query port="7001" returned 3,331,906 matches. The query port="7199" returned 1,037,743 matches.
What sits on those ports
Port 7001 is the default HTTP listener for Oracle WebLogic Server. It is the port an application server exposes when it is installed with defaults, and it is also the port the administration console frequently answers on when nobody moves it.
Port 7199 is the default JMX remote management port for Apache Cassandra. It provides a management interface to a database that holds the operational state of whatever depends on it.
The common thread here is not the vendor. It is the pattern of shipping a default management listener alongside the service it manages, on a port that is easy to leave reachable.
Why the pattern persists
Java middleware is installed by a deployment process that has to work the first time. That process enables the administration interface because it is needed during installation, and the same interface remains enabled afterwards because disabling it is a separate change with its own testing requirement.
The result is that management planes accumulate exposure over time. A WebLogic console on 7001 and a JMX listener on 7199 are not the application; they are the interfaces that can stop it, redeploy it, or read everything it holds.
Reading the numbers responsibly
Neither figure should be presented as a count of vulnerable servers. Port 7001 is answered by WebLogic instances of every version and patch level, and by other services that happen to bind there. Port 7199 is answered by Cassandra clusters in every state of configuration.
What the pair supports is a claim about architecture: default management listeners are present on publicly reachable addresses in the millions. The population of those that also lack authentication is a subset, and it is not determinable from a port count.
The inventory work
For an organisation running either product, the questions are specific. Is the administration console on 7001 reachable from anywhere other than the administrative network? Is the JMX interface on 7199 protected, or does it accept unauthenticated connections from the same network as the application?
Then check the management-plane patch state separately from the application patch state. Middleware that has been upgraded for a business reason frequently retains the console configuration it was installed with.
Finally, monitor the admin interfaces for connections from unexpected sources. A management listener that receives traffic from outside its intended network is a finding, whatever the application's own logs report.
References
- ZoomEye search for port="7001": https://www.zoomeye.ai/
- ZoomEye search for port="7199": https://www.zoomeye.ai/
- Oracle WebLogic Server documentation: https://docs.oracle.com/en/middleware/standalone/weblogic-server/
Top comments (0)