Because of timing difference it's possible to distinguish between bad padding and a MAC verification error. It's also possible to recover RSA secret.
vulners.com/securityvulns/securityvulns:doc:4102
vulners.com/securityvulns/securityvulns:doc:4209
vulners.com/securityvulns/securityvulns:doc:4222
vulners.com/securityvulns/securityvulns:doc:4252