Better to use JSTL, something like:
 <c:out value="${str}" escapeXml="false"/> 
If str comes in request, then
 <c:out value="${param.str}" escapeXml="false"/> 
Here, escapeXml="false" will indicate that the html / xml tags should be evaluated and not escaped.
 source share