One of my findings during a security audit was a password, sent as is over the network. As bad as it sounds, this happens only over HTTPS connection. Some authors suggested here that additional measures are not necessary, others point some problems as I was told in the comments.
What are the threats which are not mitigated by the TLS? Obviously, the passwords leak if TLS connection is attacked by a man-in-the-middle or compromised otherwise. Anything else?