I upgraded struts2 to 2.3.32 with no problem, but I also depend on struts2-tiles-plugin- which I can't upgrade as easily. Is this a problem or is upgrading struts2-core enough to fix the issue?
No I think. At S2-046's workaround section I read:
Another option is to remove the File Upload Interceptor from the stack
Which means that vulnerability was inside core. However, struts2-tiles-plugin
does not have dependency to core!