A recent penetration test report indicated that accessing /EWS is a vulnerability. I know that /EWS indicates access to Exchange Web Services.
My Question basically is:
1) Is this really a vulnerability? From what I see here, this does not really sound much like a vulnerability
https://msdn.microsoft.com/en-us/library/office/dd877045%28v=exchg.140%29.aspx, it mostly shows details that I could already access using my credentials on Outlook Web Access.
2) Assuming it is really a vulnerability, how do I go by disabling it.