As I cannot access the server myself, I’ve asked the support to have a look. They disabled a plugin that might have influenced the delivery of iframes and I have now added the following entries to the .htaccess:
Header always unset X-Frame-Options
Header set Content-Security-Policy “frame-ancestors ‘self’ https://*”
Unfortunately it still does not work. Do you have any other idea? Thanks for your help