During a Penetration Test the "MISSING SECURITY HEADERS" vulnerbaility was flagged against CA Identity Manager (Symantec IGA)
Release : 14.x
Component : IdentityMinder(Identity Manager)
3rd Party Issue.
MISSING SECURITY HEADERS
This is not a CA Identity Manager issue, it is a 3rd party issue and needs to be resolved within the application server. See the link below for more information.
https://stackoverflow.com/questions/48643257/configure-http-headers-in-jboss-eap-7