Here's the impact, from a recently published vulnerability note:
By convincing a user to view a specially crafted HTML document (e.g., a Web page or an HTML e-mail message or attachment), an attacker may be able to execute arbitrary code with the privileges of the user. The attacker could also cause Internet Explorer (or the program using the WebBrowser control) to crash.
Fortunately, there's a patch, which is available from SAP (authentication required.)
Users unable to apply the patch, for whatever reason, also can disable the MDrmSap ActiveX control in Internet Explorer, or disable ActiveX altogether.