In One Identity OneLogin Active Directory Connector before 6.1.5, encryption of the DirectoryToken was mishandled, aka ST-812.
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.