Apache Struts 2.1.x and 2.3.x with the Struts 1 plugin might allow remote code execution via a malicious field value passed in a raw message to the ActionMessage.
View the template here CVE-2017-9791.yaml
References:
https://nvd.nist.gov/vuln/detail/CVE-2017-9791