Many good points mentioned above. While java is chosen for its ease of use and "write once, run anywhere concept," anyone really concerned with security should not be looking at java.
Enterprises that dont want java on every single desktop can develop their own solutions in-house, but that is much more costly.
Where possible; i like to rip java out completely, else turn up the HIDS & IDS.