JBoss AS administration consoles versions prior to 1.2 re-embed password that are disclosed when viewing page source. This is an obvious poor security practice and the vendor has decided not to fix it, possibly due to lack of comprehending why it is a bad idea.
c0f10c6904c19a05d1e8a3d0396455570738d1fbdff15f5f67e17fa95e061da2