Urgent.News

What's breaking now, across thousands of outlets.

Tech

3,331,906 on Port 7001 and 1,037,743 on Port 7199: Java Middleware and Its Management Ports

3,331,906 on Port 7001 and 1,037,743 on Port 7199: Java Middleware and Its Management Ports Two ports in the Java application ecosystem, both measurable in the millions, and both historically associated with remote code execution reachable without credentials. The measurement Two queries ran on 25 September 2026 with sub_type=all and pagesize 1. The query port="7001" returned 3,331,906 matches.…

In the Java application ecosystem, two ports stand out for their prominence and potential security risks: port 7001 and port 7199. These ports have been associated with remote code execution vulnerabilities that can be exploited without requiring credentials.

On September 25, 2026, two queries were run to assess the prevalence of these ports. The first query, targeting port 7001, returned 3,331,906 matches. Port 7001 serves as the default HTTP listener for Oracle WebLogic Server, which is the administration console of the application server. If not configured correctly, this port can remain open and vulnerable.

The second query, targeting port 7199, yielded 1,037,743 matches. Port 7199 is the default JMX remote management port for Apache Cassandra, a database that holds the operational state of various dependent services. This port provides a management interface for the database.

The common thread between these ports is not the vendor, but the pattern of shipping default management listeners alongside the managed services on easily reachable ports. This architectural choice, while convenient during installation, contributes to the persistent exposure of management planes over time.

Neither the port counts should be interpreted as a measure of vulnerability. Port 7001 is answered by WebLogic instances of every version and patch level, and other services may also bind to this port. Similarly, port 7199 is answered by Cassandra clusters regardless of their configuration. The real concern lies in the fact that these default management listeners are present on millions of publicly reachable addresses.

For organizations using Oracle WebLogic Server or Apache Cassandra, specific questions need to be addressed. Is the administration console on 7001 accessible from outside the administrative network? Is the JMX interface on 7199 protected or accepting unauthenticated connections from the same network as the application? Additionally, the patch status of the management plane should be checked separately from the application patch status.

While middleware may be upgraded for business reasons, it often retains the original console configuration.

Finally, it is crucial to monitor the admin interfaces for connections from unexpected sources. A management listener receiving traffic from outside its intended network is a finding, regardless of the application's own logs reporting no such activity.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Kawasaki Heavy to launch dog-shaped social robot by fiscal 2028

TOKYO (Kyodo) -- Kawasaki Heavy Industries Ltd. said Tuesday it will launch a dog-shaped social robot in fiscal 2028 in an effort to ease the burden o

  • Kawasaki Heavy to launch dog-shaped social robot Home Leo in fiscal 2028.
  • Robot named Home Leo aims to alleviate elderly care burden due to labor shortage.
  • Home Leo can converse, assist with movement and item retrieval in homes.

The Data Layer: What You Don't Own Can Testify Against You

A woman's private diary, kept in a third-party AI app, was reported to police by the company. She now faces a felony charge. This is the clearest proof yet of the layer everyone keeps forgetting.

  • Woman's private diary in AI app led to felony charge
  • Data layer encompasses exportability, encryptability, self-hostability, deletability
  • Data can be used against you, not just lost access

2026 Error Tracking vs Uptime Monitoring: Cron Heartbeat Evidence for Storefronts

TL;DR: Error tracking records crashes and thrown exceptions, but it cannot prove that a scheduled job ran. For an e-commerce system, keep three claims separate: an error event says executing code…

  • Error tracking captures application code failures but can't confirm scheduled job completion.
  • Uptime monitoring verifies external requests but doesn't ensure background jobs progress.
  • Heartbeats check for expected success signals, revealing missed cron job completions.

Japan Firms Increasingly Targeted by Cyberattacks

Tokyo, Oct. 7 (Jiji Press)--Japan has seen a spate of cyberattacks targeting companies that resulted in breaches of personal information.

  • Japanese corporations increasingly targeted by cyberattacks
  • GMO Research & AI Inc. compromised 948,498 members' data
  • Mr. Max Holdings Ltd. suffered breach of 1.73 million members' data

More from Wednesday 7 October →