The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.
https://exchange.xforce.ibmcloud.com/vulnerabilities/51173
http://www.vupen.com/english/advisories/2009/1464
http://www.securityfocus.com/bid/35405