J2EE 1.3 implements WS-Security draft specification while J2EE 1.4 implements WS-Security 1.0 specification. This makes it a challenge WAS 5, which is based on J2EE 1.3, and WAS 6, which is based on J2EE 1.4, to interoperate with each other. Luckly, IBM DeveloperWorks has a 4 part article that tacles this problem:
http://www.ibm.com/developerworks/views/webservices/libraryview.jsp?search_by=tackle+ws-security+specification+interoperability+challenges