When a machine is overloaded, the masking mechanism fails and some characters from the typed password can be exposed. This exposition poses a minor security risk. The password should always be masked.
Put the passwords in their own password files (the method recommended since Application Server 8.1) and refer to these files with either the --adminpassword or --dbpasswordfile options.