Oracle claims the fix was 'security' related, and was required to prevent a sandboxed applet from obtaining access to "file path" information (the folder name where the applet is being run). But Oracle failed horrible, as explained in great detail here:
http://www.duckware.com/tech/java-security-clusterfuck.html Google "java bug report" and submit a bug report to Oracle, as Oracle needs to fix this.