You could edit the file server/xxx/deploy/jbossweb-tomcat55.sar/ROOT.war/index.html to remove the link. But someone could still access servlet if they know the URL. Another possibility is to edit the server/xxx/deploy/jbossweb-tomcat55.sar/ROOT.war/WEB-INF/web.xml file and remove the servlet and servlet-mapping entries.
The other possibility is to secure the /status context by adding a security-constraint entry to the above web.xml file.
Just completely throw out ROOT.war.
Btw.: the web-console will - if not secured - also show you at least all mbeans with all attributes. This is hidden in the management/ folder.