If I create an iframe like this:
var dialog = $(\'
you can do it in tomcat instance level config file (web.xml) need to add the 'filter' and filter-mapping' in web.xml config file. this will add the [X-frame-options = DENY] in all the page as it is a global setting.
httpHeaderSecurity
org.apache.catalina.filters.HttpHeaderSecurityFilter
true
antiClickJackingEnabled
true
antiClickJackingOption
DENY
httpHeaderSecurity
/*