Faced with same problem. Customer demands to "hide" all passwords.
So, simplest way to pass audit - from Tomcat Wiki.
Go to page http://coderstoolbox.net/string/#!encoding=xml&action=encode&charset=none and encode you pass to XML-view.
Thus - element looks like: