The Plug-in component in IBM WebSphere Application Server (WAS) before 7.0.0.15 does not properly handle trace requests, which has unspecified impact and attack vectors.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-1317
http://www.vupen.com/english/advisories/2011/0564
http://www.securityfocus.com/bid/46736