FAQ
What type of information could be disclosed by this vulnerability? An attacker who successfully exploited this vulnerability could obtain Single Sign-On (SSO) cookies in ADFS logs.
Insertion of sensitive information into log file in Active Directory Federation Services allows an unauthorized attacker to disclose information locally.