An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request containing malicious XML entities.
https://mvnrepository.com/artifact/org.powertac/server-interface
https://github.com/powertac/powertac-server/issues/1166