When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.
https://security.netapp.com/advisory/ntap-20180706-0002/
http://www.securitytracker.com/id/1039115
http://www.securityfocus.com/bid/99562
http://www.oracle.com/technetwork/security-advisory/alert-cve-2017-9805-3889403.html