The issue have been rejected.
See comment on the JIRA.
Useful article can be found here:
http://java.dzone.com/articles/understanding-web-security
Reply to this message by going to Community
Start a new discussion in JBoss Web Services at Community