Sun Java System Application Server Enterprise Edition 8.2 Release Notes for Microsoft Windows

When Running hadbm start db_name, Part of Typed Password Displayed Without Being Masked (IDs 6303581, 6346059, 6307497)

When a machine is overloaded, the masking mechanism fails and some characters from the typed password can be exposed. This exposition poses a minor security risk. The password should always be masked.

Solution

Put the passwords in their own password files (the method recommended since Application Server 8.1) and refer to these files with either the --adminpassword or --dbpasswordfile options.