A local code execution issue exists in Apache Struts2 when processing malformed XSLT files, which could let a malicious user upload and execute arbitrary files. A patch exists as of version 2.5.22.
References
https://nvd.nist.gov/vuln/detail/CVE-2012-…