The Java 2 Standard Edition 5.0 Release 4 update, issued Monday, fixes a vulnerability in Java Web Start. An application, exploiting the vulnerability, may grant itself permissions to read and write local files that are accessible to the user running the Java Web Start application.

Note: Java Web Start, as you know, allows running local applications which are dynamically updated over internet and is widely used.

The update also patches a set of bugs in the Reflection API. An applet, exploiting the vulnerability, may grant itself permissions to read and write local files or execute local applications that are accessible to the user running the untrusted applet.
Source: Apple

Apple deserves kudos for promptly updating their OS.