ehh, when you work on large systems like I do, it pays to be paranoid. May even save your job.
FYI, very few successful intrusion or security related compromises become public knowledge, especially when it's a compromise of a single or a small number of users. I'm afraid it's impossible to say one way or the other whether or not the Adobe exploit has ever happened in a production environment. I don't really see how you can make the assumption it hasn't.
And yes, there is an IT policy to disable JavaScript in browsers because I have JS disabled via an IT policy for my corporate user base. It's pretty much what this thread is about as the OP is wondering if he/she should enable the policy in BES.
