Isabella,
When applying security policies from-zone A to-zone B with match application any parameter, does it mean that
ftp, ssh, telnet, HTTP and the rest are instantly allowed for the traffic going between these zones?
R/ Yes
What exactly is covered under application any scope?
R/ Junos has predefined applications like junos-ssh, junos-telnet, etc. When you use the any option all these predefined applications are included. You can see the predefined apps with the following command:
# show configuration groups junos-defaults applications
Also, if you have configured custom applications and these use well-known ports, those apps will be included under the application any option as well. See the following link for Understanding Custom Applications:
https://www.juniper.net/documentation/en_US/junos/topics/topic-map/security-policy-custom-applications.html
I hope this helps you 😉