The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
http://www.vupen.com/english/advisories/2011/0564
http://www.securityfocus.com/bid/46736