I've seen this as a security issue several times, where older enterprise tools have embedded URL session keys (horrible, I know) or other private data, and act as the referrer to public sites. This either exposes more of these tools' data and functions to traffic sniffers, or malicious site operators.
There is no legitimate purpose to the referrer within applications that isn't replaceable via internal claims based tokens, or external sites' parameterised (thus, opt in) source tracking.