Zoho ManageEngine ServiceDesk Plus before 11302 is vulnerable to authentication bypass that allows a few REST-API URLs without authentication.
https://www.manageengine.com/products/service-desk/on-premises/readme.html#11302
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-37415