Code execution in a JVM is typically equivalent to code execution on the host where it's running.
Because this vulnerability affects both clients and servers, it sounds like a good way for someone to write a worm that ends up creating a giant botnet by spreading from servers to clients and vice-versa.