The issue affects all versions since Java SE 6 update 10. Disabling the java plugin is not sufficient to prevent exploitation, as the toolkit is installed independently.
--------------
Core Security Patterns: Best Practices and Strategies for J2EE ~ Ramesh Nagappan
Java Security ~ Scott Oaks
--------------
Core Security Patterns: Best Practices and Strategies for J2EE ~ Ramesh Nagappan
Java Security ~ Scott Oaks