It is not easy to exploit this OpenSSL bug. In fact, I don't think there are any reported cases of it ever having been exploited. It's been fixed for a while already. I believe immediately after it was fist found, it was fixed, and new software was available for immediate installation.
I'm afraid you're incorrect. This vulnerability is being exploited in the wild. In addition to other reports one of my customers was hit by it. Also, the fix for this was released on April 7th.
Unfortunately OpenSSL is a library, not a full product. What that means is that many, many products that use OpenSSL must be patched to use an unaffected version before the problem is truly solved.
Everything passing across an SSL/TLS link connected to an affected service should be considered compromised, including user credentials.