I'd wager that many if not most corporate internal networks are vulnerable to ARP poisoning. A little computer hooked up to the network via ethernet is all one would need to launch such an attack, and https is vulnerable since many users have been conditioned to click through any kind of invalid certificate warning. Consider downloading Cain&Abel and experimenting on your own home network just to see how powerful these tools are. Fortunately, methods of detecting ARP poisoning exist, but undoubtedly many IT departments invest heavily in firewalls without worrying about attacks originating from inside.