Some of you may be able to get by with disabling it, but if you're a current member of the military, you need Java to gain access to secure websites like DTS, iPerms, etc. If you aren't in the military, you may also find that some of your web services don't work without Java. All the same you wouldn't figure that out until you disable it.
The issue is vulnerability. Java has been around for a long time. And for as long as I can remember, there have always been issues. The same went for the flash technology, especially during its heyday. Now not so much because of how little it's being used. But back in the day, the permissions available to the local file enabled it to do just about whatever it wanted.
The best way to protect yourself from attacks is obviously 1) keep your antivirus definitions up to date, 2) don't click on links if you don't know where they go, and 3) Don't allow Java applets access to your computer (Java, along with flash, are required to gain user approval for any local action, that means it will ASK you for permission.) unless you're absolutely trusting of its source.