IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.11, when addNode -trace is used during node federation, allows attackers to obtain sensitive information about CIMMetadataCollectorImpl trace actions by reading the addNode.log file.
http://www.vupen.com/english/advisories/2010/1411
http://www.securityfocus.com/bid/40699
http://www-01.ibm.com/support/docview.wss?uid=swg1PM15830