The current working version of CIS does have full virtualization.
The current releases have two sandboxing techniques. The automatic sandbox is an access-rights restriction type sandbox, similar to the Chrome web browser sandbox. The manual sandbox however, is a fully virtualized environment.
In my opinion, CIS will be just as effective at stopping Java exploits as any other product.
The latest Java 7 update 10 has the option to choose how to handle Java applets in your browser. It even allows you to totally disable it.
Since Java is rarely needed on the web. The best thing to do is to disable Java in your browser from the Java Control Panel and only switch it on when going to your bank. Make sure to the security setting for Java to a high level. And of course; keep your Java updated.