If Business Activity Monitoring (BAM) is implemented on WebSphere, you should disable the serveServletsByClassnameEnabled property to prevent accessing servlets directly.
In the WebSphere administrator console, select Servers > Server Types > WebSphere Application Servers > server_name > Web Container settings > Web Container.
Under Additional Properties, click Custom Properties.
Click New.
In the Name field, specify serveServletsByClassnameEnabled.