The information for locking down JBoss AS can be found at: https://community.jboss.org/wiki/SecureJBoss
If the scanning tool is finding something beyond that, and the report it is giving you is not clear, you'll have to find out from the scanning tools owner exactly what it is looking at and what it is complaining about.