Mitigating a vulnerable jQuery 1.12.4 library

RICOH ProcessDirector bundles a vulnerable version of jQuery (1.12.4) with RicohPDFPrinter. Use this procedure to remove the vulnerable files and mitigate the vulnerability.
This mitigation applies only if this base directory exists on your system:
  • Linux:/opt/infoprint/ippd/pc
If this directory does not exist on your system, no action is required.
To mitigate the vulnerable jQuery library:
  1. Take a backup or snapshot of your system before installing any features.
  2. Install the updated features:
    • Version 3.14: ProductUpdate and Feature Manager
    • Version 3.13: ProductUpdate and RicohPDFPrinter
  3. Start RICOH ProcessDirector and check the Features page to verify that the latest versions are deployed.
  4. Identify and remove these jQuery library files:
    • /opt/infoprint/ippd/pc/ws/webapps/printing/installableOptionsTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js
    • /opt/infoprint/ippd/pc/ws/webapps/printing/importerTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js

    Run these commands to remove the files:

    rm "/opt/infoprint/ippd/pc/ws/webapps/printing/installableOptionsTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js"

    rm "/opt/infoprint/ippd/pc/ws/webapps/printing/importerTool/common/jquery/slickGrid/2.4.32/lib/jquery-1.12.4.min.js"

  5. You do not need to restart RICOH ProcessDirector after removing the files.
  6. Optional: If you created any custom PDF printers (you imported a printer GPZ file), clear your browser cache.